As cited
Copy frozen at (site build).
vulnerabilities
Buy A Help Desk, Bundle A Remote Access Solution? (SolarWinds Web Help Desk Pre-Auth RCE Chain(s))
SolarWinds Web Help Desk has been found to contain multiple pre-authentication remote code execution vulnerabilities via Java deserialization, including CVE-2025-40552, CVE-2025-40553, and CVE-2025-40554. Researchers achieved RCE on a fully patched instance by chaining an authentication bypass with a deserialization flaw, demonstrating that previous patches for similar 2024 vulnerabilities did not fully address the underlying issues. This continues a pattern of recurring deserialization problems in the product.
Why it matters: Help desk administrators running SolarWinds Web Help Desk need to immediately assess if they are exposed to pre-auth RCE and apply patches, as these vulnerabilities bypass authentication and allow unauthenticated remote code execution on internet-facing systems handling sensitive internal data.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Buy A Help Desk, Bundle A Remote Access Solution? (SolarWinds Web Help Desk Pre-Auth RCE Chain(s))
SolarWinds Web Help Desk has been found to contain multiple pre-authentication remote code execution vulnerabilities via Java deserialization, including CVE-2025-40552, CVE-2025-40553, and CVE-2025-40554. Researchers achieved RCE on a fully patched instance by chaining an authentication bypass with a deserialization flaw, demonstrating that previous patches for similar 2024 vulnerabilities did not fully address the underlying issues. This continues a pattern of recurring deserialization problems in the product.
Why it matters: Help desk administrators running SolarWinds Web Help Desk need to immediately assess if they are exposed to pre-auth RCE and apply patches, as these vulnerabilities bypass authentication and allow unauthenticated remote code execution on internet-facing systems handling sensitive internal data.
- Source published
- First seen by Cybersecurity Tracker