Find notable cyber news and cases, enriched with sources, timelines, and signals.
Vulnerability Security Patch Release

SolarWinds Web Help Desk repeat-bypass RCE and hotfix response

Updated 23.09.2025 16:41
Case score 60
Case score 60 Members 2 Latest activity 23.09.2025 16:41 Patch available CVSS: 9.8 Critical No known exploitation
Patch available CVSS: 9.8 Critical No known exploitation
Members 2 First seen 23.09.2025 15:46 Last seen 23.09.2025 16:41 Updated 23.09.2025 16:41

Overview

**SolarWinds Web Help Desk** is dealing with **CVE-2025-26399**, an unauthenticated AjaxProxy deserialization flaw that can let an attacker execute commands on the host. SolarWinds released hot fixes and told operators to move to **Web Help Desk 12.8.7 HF1**, because the issue is a patch bypass of **CVE-2024-28988** and **CVE-2024-28986**. The response centers on installing the hotfix, replacing the affected JAR files, and restarting the service. Available evidence does not show exploitation in the wild, but exposed deployments still need to treat remediation as urgent.