SolarWinds on Tuesday released a hotfix - again - for a critical, 9.8-severity flaw in its Web Help Desk IT ticketing software that could allow a remote, unauthenticated attacker to run commands on a host machine. This is the third time the vendor has tried to fix this flaw, an unauthenticated, AJAXproxy deserialization remote code execution (RCE) bug in its Web Help Desk ticketing and asset management software. "This vulnerability is a patch bypass of CVE-2024-28988, which in turn is a patch bypass of CVE-2024-28986," SolarWinds noted in its Tuesday release. Criminals exploited both of those earlier vulnerabilities. It all started in mid-August 2024, when the software maker released a hotfix for CVE-2024-28986, a critical (9.8 CVSS) deserialization RCE vulnerability in Web Help Desk. CISA later added this flaw to its Known Exploited Vulnerabilities catalog. Then in October 2024, SolarWinds disclosed and tried to patch CVE-2024-28988, another 9.8-rated Web Help Desk Java deserialization RCE bug, which Trend Micro's Zero Day Initiative (ZDI) spotted while researching CVE-2024-28986. "The ZDI team was able to discover an unauthenticated attack during their research," SolarWinds said at the time. And that brings us to CVE-2025-26399, the new vuln. "Anonymous," working with ZDI, is also credited with finding and reporting this flaw to SolarWinds. A SolarWinds spokesperson told The Register that the company is not aware of any exploitation as of yet. However, as threat intel firm ...
Third time's the charm? SolarWinds (again) patches critical Web Help Desk RCE
The Register
·Jessica Lyons
·Published Sep 23, 2025
·Updated
Affected Software
1 affected component
SolarWinds Web Help Desk
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a critical security patch released by SolarWinds for its Web Help Desk software addressing a remote code execution vulnerability.
2
What security implications are discussed in this article?
The article highlights the severe risk posed by a 9.8-severity flaw that could allow remote, unauthenticated attackers to execute commands on affected systems.
3
What products or software are affected by this vulnerability?
The vulnerability specifically affects the SolarWinds Web Help Desk IT ticketing software.
4
How many times has SolarWinds issued patches for this vulnerability?
The article indicates that SolarWinds has issued patches for this vulnerability multiple times.
5
What is the severity level of the flaw mentioned in the article?
The flaw has a severity score of 9.8, indicating it is critical.