CVE-2026-28323
SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2.0 authentication method to be enabled.
- Published Jul 30, 2026
- CVSS 9.8 critical
- 1.0% chance of exploitation in the next 30 days (EPSS)
Affected software
In the news
- ⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks The Hacker News ·
- SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE The Hacker News ·
- Multiple Vulnerabilities in SolarWinds Web Help Desk Could Allow for Authentication Bypass CIS MS-ISAC ·