CVE-2025-40551: SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2026-02-03. EPSS: 84.2% chance of exploitation in the next 30 days.

SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication.

Affected products

  • SolarWinds Web Help Desk: before 2026.1 (fixed in 2026.1)

Published 2026-01-28. Last modified 2026-06-17.