Vulnerability record · CVE-2025-40553 · published 28 January 2026
CVE-2025-40553: SolarWinds Web Help Desk unauthenticated deserialization RCE
Solarwinds · Web Help Desk
SolarWinds Web Help Desk is affected by an untrusted data deserialization flaw (CWE-502) that can lead to remote code execution. The vulnerability is reachable without authentication, so any network-exposed instance is at risk of full host compromise.
Description
SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable remote code execution with a CVSS of 9.8 and very high EPSS probability makes this an urgent patch target.
What it is
SolarWinds Web Help Desk is affected by an untrusted data deserialization flaw (CWE-502) that can lead to remote code execution. The vulnerability is reachable without authentication, so any network-exposed instance is at risk of full host compromise.
Impact
An attacker can execute arbitrary commands on the host running Web Help Desk, gaining code execution in the context of the service. That enables data theft, lateral movement and full control of the affected server.
Attack surface
Reached over the network via the Web Help Desk service; the CVSS vector (AV:N/PR:N/UI:N) and the description state no authentication and no user interaction are required. Any internet- or network-exposed instance is directly reachable.
Exploitation
Not listed in CISA KEV and no ransomware association is documented, but EPSS is 0.6039 (99.1st percentile), indicating high predicted exploitation activity. A public proof-of-concept script is referenced on GitHub, so working exploit code appears to be available.
What to do
- Apply the fixed release noted in the SolarWinds Web Help Desk 2026.1 release notes and vendor advisory for CVE-2025-40553.
- If patching cannot be done immediately, restrict network access to Web Help Desk to trusted management networks and block it from the internet.
- Run the Web Help Desk service with least privilege and isolate it from sensitive internal systems.
- Monitor the vendor advisory and release notes for any additional hardening guidance.
Detection
- Hunt for unexpected child processes spawned by the Web Help Desk service (for example cmd.exe, powershell.exe, /bin/sh) on Web Help Desk hosts.
- Review Web Help Desk HTTP logs for anomalous POST requests or serialized payload patterns to application endpoints.
- Alert on outbound network connections from Web Help Desk hosts to unfamiliar external addresses.
- Correlate host process creation and network telemetry around Web Help Desk with known exploitation indicators from the public PoC.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2025-40553 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-40553), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.