• News/
  • https://www.theregister.com/2026/02/04/critical_solarwinds_web_help_desk/

Critical SolarWinds Web Help Desk bug under attack

The Register
·
Jessica Lyons
·
Published Feb 4, 2026
·
Updated

Attackers are exploiting a critical SolarWinds Web Help Desk bug - less than a week after the vendor disclosed and fixed the 9.8-rated flaw. That's according to America's lead cyber-defense agency, which set a Friday deadline for federal agencies to patch the security flaw. The vulnerability under attack, CVE-2025-40551, is an untrusted deserialization flaw that can lead to remote code execution, allowing a remote, unauthenticated attacker to execute OS commands on the affected system. SolarWinds fixed the security hole, along with five others, in Web Help Desk version 2026.1, released on January 28. Horizon3.ai and watchTowr researchers reported these six bugs to the software vendor, with Horizon3 warning that "these vulnerabilities are easily exploitable." While there weren't any known cases of in-the-wild exploitation at the time of disclosure, Rapid7 threat hunters said "we expect this to change as and when technical details become available." Plus, they pointed out, SolarWinds' Web Help Desk product has made two previous appearances, both times in 2024, in CISA's Known Exploited Vulnerabilities catalog, "indicating that it is a target for real-world attackers." These were CVE-2024-28987, a critical, hardcoded login credential bug and CVE-2024-28986, a deserialization RCE vulnerability that was patched three times before the fix worked and attackers weren't able to bypass it. While we don't know who is attacking the latest Web Help Desk vulnerability, or what they are doi...

Read full article

Affected Software

1 affected component
SolarWinds Web Help Desk=2026.1
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main issue discussed in the article?

The article discusses a critical vulnerability in SolarWinds Web Help Desk that is currently being exploited by attackers.

2

What is the severity rating of the SolarWinds Web Help Desk vulnerability?

The vulnerability has a severity rating of 9.8, indicating critical risk.

3

Which version of SolarWinds Web Help Desk is affected by this bug?

The affected version of SolarWinds Web Help Desk is 2026.1.

4

What immediate action has been advised for federal agencies in response to this vulnerability?

Federal agencies have been given a deadline to patch the vulnerability promptly due to ongoing attacks.

5

Who reported the exploitation of the SolarWinds Web Help Desk vulnerability?

The exploitation of the vulnerability has been reported by America's lead cyber-defense agency.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203