SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could allow an unauthenticated attacker to gain access to certain restricted functionality.
https://www.solarwinds.com/trust-center/security-advisories/CVE-2025-40536
https://www.huntress.com/blog/active-exploitation-solarwinds-web-help-desk-cve-2025-26399
https://www.securityweek.com/cisa-warns-of-exploited-solarwinds-notepad-microsoft-vulnerabilities/
https://thehackernews.com/2026/02/researchers-observe-in-wild.html
https://www.theregister.com/2026/02/09/solarwinds_mystery_whd_attack/
https://www.securityweek.com/recent-solarwinds-flaws-potentially-exploited-as-zero-days/
https://thehackernews.com/2026/02/solarwinds-web-help-desk-exploited-for.html
https://thehackernews.com/2026/02/cisa-adds-actively-exploited-solarwinds.html
https://www.securityweek.com/solarwinds-patches-critical-web-help-desk-vulnerabilities/
https://www.helpnetsecurity.com/2026/01/29/solarwinds-web-help-desk-rce-vulnerabilities/
https://thehackernews.com/2026/01/solarwinds-fixes-four-critical-web-help.html