Skip to content
COOEY

FAIL › dossier

Web Help Desk

PRODUCT

· dossier confidence 20%

PROFILE
CategoryHelp Desk SoftwareWhat they doSolarWinds Web Help Desk is a cloud-based platform designed to streamline IT service management and support processes for organizations. Websitehttps://www.solarwinds.com/en/products/web-help-desk/ ↗
SECURITY POSTURE

The company has faced multiple security breaches, indicating potential vulnerabilities in its product.

Notable failures
  • CVE-2025-26399: High [RCE] - Remote command execution via untrusted data deserialization
  • CVE-2025-40536: High [RCE] - Unpatched RCE vulnerability
  • CVE-2025-40551: High [RCE] - Deserialization of untrusted data vulnerability leading to remote code execution
  • CVE-2025-28986: High [RCE] - Deserialization of untrusted data vulnerability
  • CVE-2025-28987: High - Hardcoded credential vulnerability
Patterns: Repeated unpatched RCE vulnerabilities; Deserialization vulnerabilities leading to remote code execution; Hardcoded credentials leading to unauthorized access
FAILURE HISTORY · 5
DATEEVENTSEVSUMMARY
2026-03-09 CVE-2025-26399 high SolarWinds Web Help Desk allows remote command execution via untrusted data deserialization in AjaxProxy.
2024-10-15 CVE-2024-28987 high SolarWinds Web Help Desk allows remote unauthenticated access via hardcoded credentials, enabling data modification.
2024-08-15 CVE-2024-28986 high SolarWinds Web Help Desk allows remote code execution via deserialization of untrusted data, a high-severity vulnerability actively exploited in the wild.
2026-02-12 CVE-2025-40536 high SolarWinds Web Help Desk unpatched RCE
2026-02-03 CVE-2025-40551 high SolarWinds Web Help Desk RCE due to untrusted data deserialization
Open questions: How has the company addressed the noted security failures? · What is the current state of the product's security posture? · Are there any long-term implications for the company's reputation and customer trust?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-23 03:40:49.442108+00:00