CVE-2025-26399CRITICAL 9.8CISA KEVEPSS p99.8%

CVE-2025-26399SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability

SolarWinds / Web Help Desk

Description

SolarWinds Web Help Desk contain a deserialization of untrusted data vulnerability in AjaxProxy that could allow an attacker to run commands on the host machine.

Scoring

CVSS 3.19.8 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS88.53% probability of exploitation · percentile 99.8% · 2026-06-15T12:03:41Z
Published2025-09-23
Last modified2026-03-10

CISA KEV entry

Added to KEV: 2026-03-09

Underlying weaknesses· 1

CWE-502

References

  1. https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_12-8-7-hotfix-1_release_notes.htm
  2. https://www.solarwinds.com/trust-center/security-advisories/CVE-2025-26399
  3. https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-26399
  4. https://www.microsoft.com/en-us/security/blog/2026/02/06/active-exploitation-solarwinds-web-help-desk/

1

TypeTargetConfidenceTier
WeaknessDeserialization of Untrusted Datacwe-5020%live

(incoming)1

TypeTargetConfidenceTier
KEVEntrySolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerabilitykev-cve-2025-263990%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-40553
CVE
SolarWinds Web Help Desk Hardcoded Credential Vulnerability
CVE
CVE-2025-40554
CVE
CVE-2025-40552
CVE
SolarWinds Web Help Desk Security Control Bypass Vulnerability
CVE
Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.