Critical SolarWinds Web Help Desk Vulnerabilities Patched

SolarWinds patches critical flaws enabling unauthenticated remote takeover of systems.

  • SolarWinds released security updates for its Web Help Desk software to address six severe vulnerabilities, four of which are critical with CVSS scores of 9.8.
  • The critical flaws allow unauthenticated attackers to bypass authentication and achieve remote code execution (RCE) on affected systems, giving them control over the host machine.
  • Researchers from Horizon3.ai and watchTowr discovered the vulnerabilities, with some similar past SolarWinds flaws already cataloged as actively exploited.

SolarWinds patched multiple critical security flaws in its Web Help Desk software on January 29, 2026, after researchers found severe vulnerabilities enabling total system takeover. Among the six issues are four critical vulnerabilities rated 9.8 on the CVSS scale, which allow unauthenticated remote code execution.

- Advertisement -

Two of the critical flaws, CVE-2025-40551 and CVE-2025-40553, are untrusted data deserialization issues that let attackers run arbitrary commands. Consequently, an RCE via deserialization is a highly reliable vector for attackers to leverage. The other two critical flaws, CVE-2025-40552 and CVE-2025-40554, are authentication bypasses that can also lead to RCE.

Researchers Jimi Sebree from Horizon3.ai and Piotr Bazydlo from watchTowr discovered the vulnerabilities, which are all fixed in WHD 2026.1. Meanwhile, a detailed post by Sebree described CVE-2025-40551 as a deserialization issue from the AjaxProxy functionality.

The company has a history of patching similar flaws in Web Help Desk, including CVE-2024-28986 and CVE-2024-28987. Previously, the U.S. Cybersecurity and Infrastructure Security Agency added those older flaws to its Known Exploited Vulnerabilities catalog due to active exploitation. Therefore, customers must urgently update to the latest version to mitigate this significant risk.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

- Advertisement -

Previous Articles:

- Advertisement -

Latest News

MSTR Rebounds as Bitcoin Holds Above $67,000

MicroStrategy stock is up 8% this week to $132, signaling a potential rebound after...

Bitcoin surges after Supreme Court limits Trump tariffs

The Supreme Court ruled that most of President Donald Trump's tariffs were imposed by...

Google Boosts Funding to Partners to Rival Nvidia

Google is boosting financial support to data-center partners to spur adoption of its AI...

Aave Dev Team BGD Labs Exits Amid DAO Conflict

BGD Labs, the key developer of Aave v3, is ending its service contract with...

Aave’s BGD Labs Ends 4-Year DAO Partnership

BGD Labs, a primary developer for the Aave protocol, announced it will end its...

Must Read

9 DePIN Programs For Passive Income

Here’s something most people don’t realize: your smartphone and PC can generate passive income with almost no effort.I’m not talking about clicking ads for...
🔥 #AD Get 20% OFF any new 12 month hosting plan from Hostinger. Click here!