BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Critical SolarWinds Web Help Desk Vulnerabilities Patched

SolarWinds patches critical flaws enabling unauthenticated remote takeover of systems.

  • SolarWinds released security updates for its Web Help Desk software to address six severe vulnerabilities, four of which are critical with CVSS scores of 9.8.
  • The critical flaws allow unauthenticated attackers to bypass authentication and achieve remote code execution (RCE) on affected systems, giving them control over the host machine.
  • Researchers from Horizon3.ai and watchTowr discovered the vulnerabilities, with some similar past SolarWinds flaws already cataloged as actively exploited.

SolarWinds patched multiple critical security flaws in its Web Help Desk software on January 29, 2026, after researchers found severe vulnerabilities enabling total system takeover. Among the six issues are four critical vulnerabilities rated 9.8 on the CVSS scale, which allow unauthenticated remote code execution.

- Advertisement -

Two of the critical flaws, CVE-2025-40551 and CVE-2025-40553, are untrusted data deserialization issues that let attackers run arbitrary commands. Consequently, an RCE via deserialization is a highly reliable vector for attackers to leverage. The other two critical flaws, CVE-2025-40552 and CVE-2025-40554, are authentication bypasses that can also lead to RCE.

Researchers Jimi Sebree from Horizon3.ai and Piotr Bazydlo from watchTowr discovered the vulnerabilities, which are all fixed in WHD 2026.1. Meanwhile, a detailed post by Sebree described CVE-2025-40551 as a deserialization issue from the AjaxProxy functionality.

The company has a history of patching similar flaws in Web Help Desk, including CVE-2024-28986 and CVE-2024-28987. Previously, the U.S. Cybersecurity and Infrastructure Security Agency added those older flaws to its Known Exploited Vulnerabilities catalog due to active exploitation. Therefore, customers must urgently update to the latest version to mitigate this significant risk.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

- Advertisement -

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Coldcard Hack Ongoing: $88M Stolen in Three Waves

Galaxy Research now tracks roughly $88.6 million stolen from approximately 4,585 Coldcard addresses across...

STRC shares stay below $100 par, August dividend holds at 12%

Strategy's STRC preferred shares closed July at $89.46, well below their $100 par value,...

Can Apple Stock Double by 2030?

Apple trades near $295 as debate intensifies over whether the stock can double by...

Meta’s AI ‘pervert glasses’ spark privacy lawsuits and bans

Meta's AI-powered Ray-Ban smart glasses are facing a severe privacy backlash in 2026, with...

BNB Chain sues ex-employee over unauthorized memecoin

BNB Chain is pursuing legal action after a former employee allegedly used unauthorized access...

Must Read

What Is a Sim Swap Hack?

You've likely heard the term 'sim-swap,' but do you really know what it means? It's a type of fraud that's rapidly increasing, where scammers...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading