SolarWinds Web Help Desk Vulnerability Allows Unauthenticated RCE
SolarWinds has issued an urgent advisory regarding a critical vulnerability in its Web Help Desk software, identified as CVE-2025-26399, which allows unauthenticated remote code execution (RCE) with a severity rating of 9.8 out of 10. This flaw stems from the deserialization of untrusted data and represents a patch bypass for two previously resolved vulnerabilities, indicating a recurring weakness in the software. SolarWinds has released a hotfix for version 12.8.7 and strongly urges users to install it to prevent potential remote attacks. The discovery highlights the ongoing challenges in software security, underscoring the need for robust mitigation strategies to protect against evolving cyber threats in an increasingly digital landscape.
