Vulnerability
Security Patch Release
SolarWinds Web Help Desk repeat-bypass RCE and hotfix response
Updated 23.09.2025 16:41
Case score 60
Why this score?
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 60
- Main story score
- 60
- Related evidence lift
- +0 / 20
- Contributing updates
- 0
- Context updates
- 1
Top contributors
- Vulnerability Anchors the case with the critical unauthenticated RCE flaw in SolarWinds Web Help Desk. main
- Security Patch Release Provides remediation context, including the hotfix and upgrade path for CVE-2025-26399. context
Members 2
First seen 23.09.2025 15:46
Latest activity 23.09.2025 16:41
Overview
**SolarWinds Web Help Desk** is dealing with **CVE-2025-26399**, an unauthenticated AjaxProxy deserialization flaw that can let an attacker execute commands on the host. SolarWinds released hot fixes and told operators to move to **Web Help Desk 12.8.7 HF1**, because the issue is a patch bypass of **CVE-2024-28988** and **CVE-2024-28986**.
The response centers on installing the hotfix, replacing the affected JAR files, and restarting the service. Available evidence does not show exploitation in the wild, but exposed deployments still need to treat remediation as urgent.
Latest development
SolarWinds details CVE-2025-26399 patch bypass and discovery
SolarWinds characterized CVE-2025-26399 as a CVSS 9.8 deserialization vulnerability that is a patch bypass for CVE-2024-28988 and CVE-2024-28986, with the original bug first addressed in August 2024. An anonymous researcher working with Trend Micro Zero Day Initiative (ZDI) was credited with discovering and reporting the flaw, and SolarWinds said there was no evidence of exploitation in the wild.
SolarWinds Web Help Desk 12.8.7 contains **CVE-2025-26399**, an unsafe-deserialization flaw in **AjaxProxy** that can let an unauthenticated attacker execute commands on the host.
SolarWinds issued hot fixes and told operators to move to **Web Help Desk 12.8.7 HF1** to close the issue. The advisory says the flaw is a patch bypass of **CVE-2024-28988**, which itself bypassed **CVE-2024-28986**. The remediation path includes replacing specific JAR files, deleting **c3p0.jar**, copying the hotfix-supplied JARs, adding **HikariCP.jar**, and restarting the service.
The vendor said there was no evidence of exploitation in the wild at publication. The affected surface is a server-side help desk platform used by IT support teams, so exposed deployments should treat the fix as urgent even though reach is unquantified.
Signals
Exploitation
Affected impact
CVEs/products
Geographic context
Remediation
Technical intelligence
Existing Case dataMember happenings
Vulnerability
SolarWinds Web Help Desk unsafe deserialization RCE (CVE-2025-26399)
Exploitation
No Known Exploitation
Exploit
No Known Public Exploit
Data Type
Passwords
Patch
Patch Available
Vulnerability
SolarWinds Web Help Desk unsafe deserialization RCE (CVE-2025-26399)
Exploitation
No Known Exploitation
Exploit
No Known Public Exploit
Data Type
Passwords
Patch
Patch Available
Security Patch Release
SolarWinds security patch release for CVE-2025-26399
Exploitation
No Known Exploitation
CVSS
9.8 Critical
Urgency
High
Patch
Patch Available
Security Patch Release
SolarWinds security patch release for CVE-2025-26399
Exploitation
No Known Exploitation
CVSS
9.8 Critical
Urgency
High
Patch
Patch Available