CVE-2025-40536: SolarWinds Web Help Desk Security Control Bypass Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2026-02-12. EPSS: 73.6% chance of exploitation in the next 30 days.

SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could allow an unauthenticated attacker to gain access to certain restricted functionality.

Affected products

  • SolarWinds Web Help Desk: before 2026.1 (fixed in 2026.1)

Published 2026-01-28. Last modified 2026-06-17.