SolarWinds Web Help Desk

7 known vulnerabilities in SolarWinds Web Help Desk, 6 critical, 5 actively exploited, with patch priority, exploit likelihood and the news covering them.

Recently exploited

  • CVE-2025-40551 CVSS 9.8 critical · actively exploited SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability
  • CVE-2025-40536 CVSS 9.8 critical · actively exploited SolarWinds Web Help Desk Security Control Bypass Vulnerability
  • CVE-2025-26399 CVSS 9.8 critical · actively exploited SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability
  • CVE-2024-28987 CVSS 9.1 critical · actively exploited SolarWinds Web Help Desk Hardcoded Credential Vulnerability
  • CVE-2024-28986 CVSS 9.8 critical · actively exploited SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability

Latest vulnerabilities

  • CVE-2026-28323 CVSS 9.8 critical SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2.0 authentication…
  • CVE-2026-28299 CVSS 7.5 high SolarWinds Web Help Desk is found to be affected by a denial-of-service vulnerability, which when exploited, could cause the Web Help Desk…
  • CVE-2025-40551 CVSS 9.8 critical · actively exploited SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability
  • CVE-2025-40536 CVSS 9.8 critical · actively exploited SolarWinds Web Help Desk Security Control Bypass Vulnerability
  • CVE-2025-26399 CVSS 9.8 critical · actively exploited SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability
  • CVE-2024-28987 CVSS 9.1 critical · actively exploited SolarWinds Web Help Desk Hardcoded Credential Vulnerability
  • CVE-2024-28986 CVSS 9.8 critical · actively exploited SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability