Security Control Bypass in SolarWinds Web Help Desk
CVE-2025-40536

8.1HIGH

Key Information:

Vendor

Solarwinds

Vendor
CVE Published:
28 January 2026

Badges

πŸ’° RansomwareπŸ‘Ύ Exploit Exists🟣 EPSS 66%πŸ¦… CISA ReportedπŸ“° News Worthy

What is CVE-2025-40536?

SolarWinds Web Help Desk is vulnerable to a security control bypass that enables an unauthenticated attacker to access restricted functionalities. If exploited, this flaw could compromise the integrity of the system, potentially allowing malicious actions without proper authentication. Addressing this vulnerability promptly is crucial for maintaining system security and protecting sensitive information.

CISA has reported CVE-2025-40536

CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2025-40536 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace as recent news articles suggest the vulnerability is being used by ransomware groups.

The CISA's recommendation is: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Web Help Desk 12.8.8 HF1 and below

News Articles

CISA orders federal agencies to patch exploited SolarWinds, Apple, Microsoft bugs within weeks

The Cybersecurity and Infrastructure Security Agency (CISA) added ten new vulnerabilities to its catalog of exploited bugs this week, forcing all federal civilian agencies to resolve the issues by the first week of March.

1 week ago

CISA adds SolarWinds, Microsoft, Apple, Notepad++ vulnerabilities to KEV catalog

The Microsoft Configuration Manager vulnerability, patched in 2024, could enable RCE.

2 weeks ago

Researchers Observe In-the-Wild Exploitation of BeyondTrust CVSS 9.9 Vulnerability

Active exploitation of BeyondTrust enables unauthenticated RCE as CISA adds Apple, Microsoft, SolarWinds, and Notepad++ flaws to KEV list.

2 weeks ago

References

EPSS Score

66% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • πŸ’°

    Used in Ransomware

  • πŸ“°

    First article discovered by SecurityWeek

  • πŸ‘Ύ

    Exploit known to exist

  • πŸ¦…

    CISA Reported

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jimi Sebree working with Horizon3.ai
.