Vulnerability record · CVE-2025-26399 · published 23 September 2025
CVE-2025-26399: SolarWinds Web Help Desk unauthenticated deserialization RCE
Solarwinds · Web Help Desk
SolarWinds Web Help Desk contains an unauthenticated deserialization flaw in the AjaxProxy component that allows remote code execution on the host. It is a patch bypass of CVE-2024-28988, which itself bypassed CVE-2024-28986, so prior fixes did not fully close the underlying issue. The flaw is remotely reachable without credentials and carries a critical CVSS score of 9.8.
Description
SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. This vulnerability is a patch bypass of CVE-2024-28988, which in turn is a patch bypass of CVE-2024-28986.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable RCE with a 9.8 CVSS score, active exploitation, KEV listing with ransomware use, and a very high EPSS probability.
What it is
SolarWinds Web Help Desk contains an unauthenticated deserialization flaw in the AjaxProxy component that allows remote code execution on the host. It is a patch bypass of CVE-2024-28988, which itself bypassed CVE-2024-28986, so prior fixes did not fully close the underlying issue. The flaw is remotely reachable without credentials and carries a critical CVSS score of 9.8.
Impact
An attacker can execute arbitrary commands on the Web Help Desk host, leading to full compromise of the application server and any data or credentials it holds. Given the KEV listing notes known ransomware campaign use, this can serve as an initial access vector for broader network compromise.
Attack surface
Reached over the network via the AjaxProxy endpoint with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any internet- or network-exposed Web Help Desk instance is a candidate target.
Exploitation
Listed in CISA KEV with a due date of 2026-03-12 and flagged for known ransomware campaign use; EPSS 30-day probability is 0.895 (99.8th percentile). A Microsoft security blog reference describes active exploitation, confirming real-world attacks.
What to do
- Apply the SolarWinds Web Help Desk 12.8.7 Hotfix 1 or later per the vendor advisory, since this is a patch bypass of earlier fixes.
- If patching cannot be done immediately, restrict network access to the Web Help Desk AjaxProxy endpoint and remove direct internet exposure.
- Follow CISA KEV required actions and BOD 22-01 guidance, including discontinuing use if mitigations are unavailable.
- Audit for prior compromise given the history of bypassed patches and active exploitation.
- Monitor vendor advisories for further bypasses of this fix chain.
Detection
- Inspect Web Help Desk and host logs for unexpected child processes spawned by the application server, especially command shells.
- Monitor AjaxProxy requests for anomalous or malformed serialized payloads and unusual POST bodies.
- Alert on outbound network connections from the Web Help Desk host to unfamiliar destinations.
- Review for webshell or dropped file artifacts in Web Help Desk directories and web-accessible paths.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-26399 to the Known Exploited Vulnerabilities catalog on 9 March 2026 as "SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 12 March 2026.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2025-26399 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-26399), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.