CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

CVE-2025-40551: Another Solarwinds Web Help Desk Deserialization Issue

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6757

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2025-40551: Another Solarwinds Web Help Desk Deserialization Issue

A deserialization vulnerability tracked as CVE-2025-40551 affects SolarWinds Web Help Desk and allows unauthenticated attackers to execute remote code. The vulnerability has a CVSS score of 9.8 and is actively exploited in the wild. SolarWinds has patched the issue in Web Help Desk version 2026.1.

Why it matters: Organizations running vulnerable SolarWinds Web Help Desk instances need to patch immediately to version 2026.1 because unauthenticated attackers are actively exploiting this high-severity remote code execution flaw.

VendorsSolarWinds
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary