CVE-2024-28987: SolarWinds Web Help Desk Hardcoded Credential Vulnerability

Critical severity, CVSS 9.1. Actively exploited: in CISA KEV since 2024-10-15. EPSS: 93.3% chance of exploitation in the next 30 days.

The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify data.

Affected products

  • SolarWinds Web Help Desk: before 12.8.3 (fixed in 12.8.3); version 12.8.3 only

Published 2024-08-21. Last modified 2026-06-17.