SolarWinds Web Help Desk Multiple Vulnerabilities
RISK: Extremely High Risk
TYPE: Clients - Productivity Products

Multiple vulnerabilities were identified in SolarWinds Web Help Desk. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution, elevation of privilege and security restriction bypass on the targeted system.
Note:
CVE-2025-40551 is actively exploited in the wild. An unauthenticated attacker could exploit an untrusted data deserialization vulnerability, leading to remote code execution. Hence, the risk level is rated as Extremely High Risk.
CVE-2025-40536 is actively exploited in the wild. A security control bypass vulnerability could allow an unauthenticated attacker to gain access to certain restricted functionality. Hence, the risk level is rated as High Risk.
[Updated on 2026-02-04]
Updated Description, Related Links and Risk Level.
[Updated on 2026-02-13]
Updated Description and Related Links.
Impact
- Remote Code Execution
- Security Restriction Bypass
- Elevation of Privilege
System / Technologies affected
- SolarWinds Web Help Desk 12.8.8 HF1 and all previous versions
Solutions
Before installation of the software, please visit the software vendor web-site for more details.
Apply fixes issued by the vendor:
- Update to SolarWinds Web Help Desk version 2026.1 or later
Vulnerability Identifier
Source
Related Link
- https://www.solarwinds.com/trust-center/security-advisories/cve-2025-40536
- https://www.solarwinds.com/trust-center/security-advisories/cve-2025-40537
- https://www.solarwinds.com/trust-center/security-advisories/cve-2025-40551
- https://www.solarwinds.com/trust-center/security-advisories/cve-2025-40552
- https://www.solarwinds.com/trust-center/security-advisories/cve-2025-40553
- https://www.solarwinds.com/trust-center/security-advisories/cve-2025-40554
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2025-40551
- https://www.cisa.gov/news-events/alerts/2026/02/12/cisa-adds-four-known-exploited-vulnerabilities-catalog
Related Tags
Share with
