Skip to content
COOEY

EXPOSURES › CVE-2025-40551

CVE-2025-40551

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-02-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2025-40551 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 rceexploited-in-wildunpatched

SolarWinds Web Help Desk RCE due to untrusted data deserialization

SolarWinds Web Help Desk, a product used by DIB, had a critical vulnerability that allowed remote code execution without authentication, leading to potential unauthorized command execution on host machines.

Shame score — Critical remote code execution flaw exploited without patch, impacting DIB organizations using the product.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

SolarWinds Web Help Desk contains a deserialization of untrusted data vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.