• News/
  • https://www.theregister.com/2025/09/23/solarwinds_patches_rce/

Third time's the charm? SolarWinds (again) patches critical Web Help Desk RCE

The Register
·
Jessica Lyons
·
Published Sep 23, 2025
·
Updated

SolarWinds on Tuesday released a hotfix - again - for a critical, 9.8-severity flaw in its Web Help Desk IT ticketing software that could allow a remote, unauthenticated attacker to run commands on a host machine. This is the third time the vendor has tried to fix this flaw, an unauthenticated, AJAXproxy deserialization remote code execution (RCE) bug in its Web Help Desk ticketing and asset management software. "This vulnerability is a patch bypass of CVE-2024-28988, which in turn is a patch bypass of CVE-2024-28986," SolarWinds noted in its Tuesday release. Criminals exploited both of those earlier vulnerabilities. It all started in mid-August 2024, when the software maker released a hotfix for CVE-2024-28986, a critical (9.8 CVSS) deserialization RCE vulnerability in Web Help Desk. CISA later added this flaw to its Known Exploited Vulnerabilities catalog. Then in October 2024, SolarWinds disclosed and tried to patch CVE-2024-28988, another 9.8-rated Web Help Desk Java deserialization RCE bug, which Trend Micro's Zero Day Initiative (ZDI) spotted while researching CVE-2024-28986. "The ZDI team was able to discover an unauthenticated attack during their research," SolarWinds said at the time. And that brings us to CVE-2025-26399, the new vuln. "Anonymous," working with ZDI, is also credited with finding and reporting this flaw to SolarWinds. A SolarWinds spokesperson told The Register that the company is not aware of any exploitation as of yet. However, as threat intel firm ...

Read full article

Affected Software

1 affected component
SolarWinds Web Help Desk
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical security patch released by SolarWinds for its Web Help Desk software addressing a remote code execution vulnerability.

2

What security implications are discussed in this article?

The article highlights the severe risk posed by a 9.8-severity flaw that could allow remote, unauthenticated attackers to execute commands on affected systems.

3

What products or software are affected by this vulnerability?

The vulnerability specifically affects the SolarWinds Web Help Desk IT ticketing software.

4

How many times has SolarWinds issued patches for this vulnerability?

The article indicates that SolarWinds has issued patches for this vulnerability multiple times.

5

What is the severity level of the flaw mentioned in the article?

The flaw has a severity score of 9.8, indicating it is critical.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203