SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that if exploited, would allow a malicious actor to execute actions and methods that should be protected by authentication.
https://www.infosecurity-magazine.com/news/solarwinds-web-help-desk/
https://thehackernews.com/2026/02/cisa-adds-actively-exploited-solarwinds.html
https://www.securityweek.com/solarwinds-patches-critical-web-help-desk-vulnerabilities/
https://www.helpnetsecurity.com/2026/01/29/solarwinds-web-help-desk-rce-vulnerabilities/
https://thehackernews.com/2026/01/solarwinds-fixes-four-critical-web-help.html
Published: 2026-01-28
Updated: 2026-02-03
Base Score: 10
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Severity: Critical
Base Score: 9.8
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity: Critical
EPSS: 0.00046
Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.
Vulnerability Being Monitored