CVE-2025-40552: SolarWinds Web Help Desk

Critical severity, CVSS 9.8. EPSS: 52% chance of exploitation in the next 30 days.

SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that if exploited, would allow a malicious actor to execute actions and methods that should be protected by authentication.

Affected products

  • SolarWinds Web Help Desk: before 2026.1 (fixed in 2026.1)

Published 2026-01-28. Last modified 2026-06-17.