CVE-2025-40554CRITICAL 9.8EPSS p99.0%
CVE-2025-40554CVE-2025-40554
Description
SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that, if exploited, could allow an attacker to invoke specific actions within Web Help Desk.
Scoring
| CVSS 3.1 | 9.8 (CRITICAL) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 57.31% probability of exploitation · percentile 99.0% · 2026-06-19T12:03:05Z |
| Published | 2026-01-28 |
| Last modified | 2026-02-03 |
Underlying weaknesses· 1
References
1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Weak Authenticationcwe-1390 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.