Vulnerability Intelligence Report
SolarWinds Web Help Desk Deserialization of Untrusted Data Privilege Escalation Vulnerability
CVE-2025-26399
SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. This vulnerability is a patch bypass of CVE-2024-28988, which in turn is a patch bypass of CVE-2024-28986.
CISA KEV
Nuclei Template
SSVC: Active Exploitation
Automatable
Deserialization
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:88.33%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-502 ↗CWE-502: Deserialization of Untrusted Data
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| SolarWinds | Web Help Desk | 12.8.7 and below (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
CISA KEV
ACTIVE IN CATALOG
Nuclei Template
SCANNER AVAILABLE
EPSS Score
88.330%
GitHub Advisory
Vulnerability Class
Deserialization
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | SolarWinds · Vendor · USA |
| Reserved | 2025-02-08T00:19:09 |
| Published | 2025-09-23T05:07:14 |
| Last Updated | 2026-08-04T03:55:57 |
Community Chatter & Buzz