Skip to main content

CVE detail

CVE-2024-28988

SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. This vulnerability was found by the ZDI team after researching a previous vulnerability and providing this report. The ZDI team was able to discover an unauthenticated attack during their research.  We recommend all Web Help Desk customers apply the patch, which is now available.  We thank Trend Micro Zero Day Initiative (ZDI) for its ongoing partnership in coordinating with SolarWinds on responsible disclosure of this and other potential vulnerabilities.

CVSS 9.8 · CriticalBuzz score 45.6

Buzz score

Why this CVE is surfacing

Buzz score total 45.6

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 25.6 · diversity 20.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Mention score
25.6
12 evidence mentions in the snapshot
Diversity score
20.0
7 sources across 3 categories
KEV score
0.0
No KEV entry observed
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
12 source links · newest first
  • 16th March – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 16th March, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES United States-based medical technology company Stryker has suffered a cyberattack that caused a global disruption to its environment. The company said its surgical robotics, clinical communications platform, and life support monitors are […]

    vendorresearch.checkpoint.comMar 16, 2026, 3:09 PM
  • CISA has added the high-severity authentication bypass vulnerability to its KEV list, along with SolarWinds and Workspace One bugs.

    newswww.securityweek.comMar 10, 2026, 11:51 AM
  • 2nd March – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 2nd March, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Wynn Resorts, a United States-based casino and hotel operator, has confirmed that employee data was accessed following an extortion threat linked to ShinyHunters. The company said operations were not disrupted. Reports indicate […]

    vendorresearch.checkpoint.comMar 2, 2026, 4:29 PM
  • h RCE on what was, at the time, a fully patched instance. Well-intentioned as always, our initial goal was to reproduce CVE-2025-26399 - a previously patched SolarWinds Web Help Desk deserialization RCE disclosed in 2025. The vulnerabilities we discovered are: CVE-2025-40552 / WT-2025-0099 - Authentication Bypass CVE-2025-40553 / WT-2025-0100 - Remote

    exploitlabs.watchtowr.comFeb 25, 2026, 8:06 PM
  • Vulnerable SolarWinds Web Help Desk instances were exploited in December 2025 for initial access.

    newswww.securityweek.comFeb 9, 2026, 12:42 PM
  • The four critical flaws could be exploited without authentication for remote code execution or authentication bypass.

    newswww.securityweek.comJan 29, 2026, 1:18 PM
  • CVE-2025-40551Horizon3.ai

    SolarWinds Web Help Desk Deserialization Vulnerability | Active Exploitation

    exploithorizon3.aiJan 28, 2026, 5:52 PM
  • CVE-2025-40551 details multiple chained vulnerabilities in SolarWinds Web Help Desk that allow unauthenticated attackers to achieve remote code execution on vulnerable instances.

    exploithorizon3.aiJan 28, 2026, 4:26 PM
  • SolarWinds has fixed yet another unauthenticated remote code execution vulnerability (CVE-2025-26399) in Web Help Desk (WHD), its popular web-based IT ticketing and asset management solution. While the vulnerability is currently not being leveraged by attackers, they might soon reverse-engineer the hotfix and create a working exploit. As watchTowr researchers noted, “given SolarWinds’ past, in-the-wild exploitation is highly likely.” About CVE-2025-26399 “[CVE-2025-26399] exists within the AjaxProxy class. The issue results from the lack of proper validation … More →

    newswww.helpnetsecurity.comSep 24, 2025, 1:25 PM
  • SolarWinds fixed a critical flaw in its Web Help Desk software that could allow attackers to execute arbitrary commands on vulnerable systems. SolarWinds has released hot fixes to address a critical flaw, tracked as CVE-2025-26399 (CVSS score: 9.8), affecting its Web Help Desk software. An attacker could exploit the flaw to execute arbitrary commands on susceptible […]

    newssecurityaffairs.comSep 24, 2025, 11:50 AM
  • SolarWinds has released a third patch for essentially the same critical Java deserialization vulnerability in its Web Help Desk product. The original flaw was first patched in August 2024 with warnings from CISA that it had been exploited in the wild. “This vulnerability is a patch bypass of CVE-2024-28988, which in turn is a patch […]

    newswww.csoonline.comSep 23, 2025, 9:16 PM
  • CVE-2025-26399 is a patch bypass of CVE-2024-28988, which is a patch bypass of the exploited CVE-2024-28986.

    newswww.securityweek.comSep 23, 2025, 4:43 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence
  • CVE-2025-40553

    SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to…

    CVSS 9.8 · Critical
    7 mentions
  • CVE-2025-40551

    SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to…

    CVSS 9.8 · Critical
    KEV listed14 mentions
  • CVE-2025-26399

    SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if exploited, would allow an attacke…

    CVSS 9.8 · Critical
    KEV listed27 mentions
  • CVE-2024-28986

    SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an attacker to run commands on t…

    CVSS 9.8 · Critical
    KEV listed33 mentions
  • CVE-2026-65883

    Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A forged clfgd field allows PHP objection injection and thereby…

    CVSS 10.0 · Critical
    1 mention
  • CVE-2026-58163

    Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or crashing. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from…

    CVSS 8.3 · High
    1 mention