CyberzSOC

Publication detail
← Back to advisories & guidance

2025-034: Critical Vulnerability in SolarWinds Web Help Desk ↗ source

September 24, 2025 CERT-EU Advisory

Summary

The fix provided as part of this advisory is a patch bypass of CVE-24-28988, which in turn is a patch bypass of CVE-2024-28986 [1]. It is recommended updating affected assets as soon as possible. The vulnerability CVE-2025-26399, with a CVSS score of 9.8, an unauthenticated AjaxProxy deserialisation remote code execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine [1]. SolarWinds Web Help Desk 12.8.7 and all previous versions are affected by this vulnerability. It is recommended updating affected assets as soon as possible.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2024-28986 9.8 Critical SolarWinds Web Help Desk SolarWinds Web Help Desk contains a deserialization of untrusted data vulnerability that could allow for remote code execution.
CVE-2025-26399 9.8 Critical SolarWinds Web Help Desk SolarWinds Web Help Desk contain a deserialization of untrusted data vulnerability in AjaxProxy that could allow an attacker to run commands on the h…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.