CVE-2025-40551: SolarWinds Web Help Desk Deserialization of Untrusted Data
SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability. SolarWinds Web Help Desk contains a deserialization of untrusted data vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication.
- CISA KEV-listed (remediation due 2026-02-06)
- EPSS 87.9% (99.5% percentile)