Vulnerability
Security Patch Release
SolarWinds Web Help Desk repeat-bypass RCE and hotfix response
Updated 23.09.2025 16:41
Case score 60
Score breakdown
- Total
- 60
- Lead score
- 60
- Support bonus
- +0 / 20
- Scoring support
- 0
- Context members
- 1
Top contributors
- Vulnerability Anchors the case with the critical unauthenticated RCE flaw in SolarWinds Web Help Desk. base
- Security Patch Release Provides remediation context, including the hotfix and upgrade path for CVE-2025-26399. context
Case score 60
Members 2
Latest activity 23.09.2025 16:41
Patch available
CVSS: 9.8 Critical
No known exploitation
Patch available
CVSS: 9.8 Critical
No known exploitation
Members 2
First seen 23.09.2025 15:46
Last seen 23.09.2025 16:41
Updated 23.09.2025 16:41
Overview
**SolarWinds Web Help Desk** is dealing with **CVE-2025-26399**, an unauthenticated AjaxProxy deserialization flaw that can let an attacker execute commands on the host. SolarWinds released hot fixes and told operators to move to **Web Help Desk 12.8.7 HF1**, because the issue is a patch bypass of **CVE-2024-28988** and **CVE-2024-28986**.
The response centers on installing the hotfix, replacing the affected JAR files, and restarting the service. Available evidence does not show exploitation in the wild, but exposed deployments still need to treat remediation as urgent.
SolarWinds Web Help Desk 12.8.7 contains **CVE-2025-26399**, an unsafe-deserialization flaw in **AjaxProxy** that can let an unauthenticated attacker execute commands on the host.
SolarWinds issued hot fixes and told operators to move to **Web Help Desk 12.8.7 HF1** to close the issue. The advisory says the flaw is a patch bypass of **CVE-2024-28988**, which itself bypassed **CVE-2024-28986**. The remediation path includes replacing specific JAR files, deleting **c3p0.jar**, copying the hotfix-supplied JARs, adding **HikariCP.jar**, and restarting the service.
The vendor said there was no evidence of exploitation in the wild at publication. The affected surface is a server-side help desk platform used by IT support teams, so exposed deployments should treat the fix as urgent even though reach is unquantified.