Skip to main content

CVE detail

CVE-2025-26399

SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. This vulnerability is a patch bypass of CVE-2024-28988, which in turn is a patch bypass of CVE-2024-28986.

CVSS 9.8 · CriticalBuzz score 75.0KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 75.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
30.0
27 evidence mentions in the snapshot
Diversity score
20.0
11 sources across 5 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
27 source links · newest first
  • The machine emulator has been abused in at least two different campaigns distributing ransomware and remote access tools.

    newswww.securityweek.comApr 20, 2026, 11:35 AM
  • Attackers abuse QEMU to hide malware in virtual machines, bypass detection, steal data, and deploy ransomware without leaving any trace. Sophos researchers report a rise in attackers abusing QEMU, an open-source emulator, to hide malicious activity inside virtual machines. By running malware in a VM, attackers avoid endpoint security controls and leave minimal traces on […]

    newssecurityaffairs.comApr 18, 2026, 3:20 PM
  • 16th March – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 16th March, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES United States-based medical technology company Stryker has suffered a cyberattack that caused a global disruption to its environment. The company said its surgical robotics, clinical communications platform, and life support monitors are […]

    vendorresearch.checkpoint.comMar 16, 2026, 3:09 PM
  • The US Cybersecurity and Infrastructure Security Agency (CISA) has warned that an authentication bypass vulnerability patched in Ivanti Endpoint Manager (EPM) last month is now being exploited in the wild. The agency has also updated its directive related to two Cisco Catalyst SD-WAN flaws that were also fixed last month after being used in zero-day […]

    newswww.csoonline.comMar 11, 2026, 10:46 PM
  • CISA has added the high-severity authentication bypass vulnerability to its KEV list, along with SolarWinds and Workspace One bugs.

    newswww.securityweek.comMar 10, 2026, 11:51 AM
  • U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds EPM, SolarWinds, and Omnissa Workspace One flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Apple, Rockwell, and Hikvision flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are the flaws added to the catalog: The first vulnerability added to the catalog is […]

    newssecurityaffairs.comMar 10, 2026, 9:52 AM
  • 2nd March – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 2nd March, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Wynn Resorts, a United States-based casino and hotel operator, has confirmed that employee data was accessed following an extortion threat linked to ShinyHunters. The company said operations were not disrupted. Reports indicate […]

    vendorresearch.checkpoint.comMar 2, 2026, 4:29 PM
  • h RCE on what was, at the time, a fully patched instance. Well-intentioned as always, our initial goal was to reproduce CVE-2025-26399 - a previously patched SolarWinds Web Help Desk deserialization RCE disclosed in 2025. The vulnerabilities we discovered are: CVE-2025-40552 / WT-2025-0099 - Authentication Bypass CVE-2025-40553 / WT-2025-0100 - Remote

    exploitlabs.watchtowr.comFeb 25, 2026, 8:06 PM
  • SolarWinds Web Help Desk (WHD) is under attack, with recent incidents exploiting a chain of zero-day and patched vulnerabilities dating back to late 2025, an analysis of customer reports by security company Huntress has found. Until now, it has been unclear which combination of recent WHD vulnerabilities were behind a series of compromises of customer […]

    newswww.csoonline.comFeb 10, 2026, 3:58 PM
  • Internet‑exposed and vulnerable SolarWinds Web Help Desk (WHD) instances are under attack by threat actors looking to gain an initial foothold into target organizations’ networks, Microsoft and Huntress researchers have warned. ƒ Once inside, the attackers are deploying legitimate remote access and digital forensics and incident response tools, using living-off-the-land techniques, setting up a reverse SSH shell, and stealing sensitive data. Attack details The initial access vector is known: SolarWinds WHD vulnerabilities. What’s unknown is … More →

    newswww.helpnetsecurity.comFeb 10, 2026, 11:56 AM
  • Vulnerable SolarWinds Web Help Desk instances were exploited in December 2025 for initial access.

    newswww.securityweek.comFeb 9, 2026, 12:42 PM
  • Huntress confirmed active SolarWinds Web Help Desk exploits, where attackers installed Zoho tools for persistence, and used Velociraptor for control. On February 7, 2026, Huntress investigated an active attack abusing SolarWinds Web Help Desk flaws. Attackers exploited unpatched versions to run code remotely, then quickly installed Zoho ManageEngine tools for persistent remote access and Cloudflare […]

    newssecurityaffairs.comFeb 9, 2026, 12:28 PM
  • The four critical flaws could be exploited without authentication for remote code execution or authentication bypass.

    newswww.securityweek.comJan 29, 2026, 1:18 PM
  • SolarWinds is yet again disclosing security vulnerabilities in one of its widely-used products. The company has released updates to patch six critical authentication bypass and remote command execution vulnerabilities in its Web Help Desk (WHD) IT software. These flaws could allow attackers to bypass authentication, perform remote code execution (RCE), and access certain functionality that should […]

    newswww.csoonline.comJan 29, 2026, 3:11 AM
  • CVE-2025-40551Horizon3.ai

    SolarWinds Web Help Desk Deserialization Vulnerability | Active Exploitation

    exploithorizon3.aiJan 28, 2026, 5:52 PM
  • CVE-2025-40551 details multiple chained vulnerabilities in SolarWinds Web Help Desk that allow unauthenticated attackers to achieve remote code execution on vulnerable instances.

    exploithorizon3.aiJan 28, 2026, 4:26 PM
  • 29th September – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 29th September, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Stellantis, Automotive maker giant which owns Citroën, FIAT, Jeep, Chrysler, and Peugeot, has suffered a data breach that resulted in exposure of North American customer contact information after attackers accessed a third-party […]

    vendorresearch.checkpoint.comSep 29, 2025, 12:43 PM
  • A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. Ohio’s Union County suffers ransomware attack impacting 45,000 people ForcedLeak flaw in Salesforce Agentforce exposes CRM […]

    newssecurityaffairs.comSep 28, 2025, 12:23 PM
  • Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: How Juventus protects fans, revenue, and reputation during matchdays In this Help Net Security interview, Mirko Rinaldini, Head of ICT at Juventus Football Club, discusses the club’s approach to cyber risk strategy. Juventus has developed a threat-led, outcomes-driven program that balances innovation with protections across matchdays, e-commerce, and digital platforms. Review: Practical Purple Teaming Practical Purple Teaming is a guide … More →

    newswww.helpnetsecurity.comSep 28, 2025, 8:00 AM
  • SolarWinds has fixed yet another unauthenticated remote code execution vulnerability (CVE-2025-26399) in Web Help Desk (WHD), its popular web-based IT ticketing and asset management solution. While the vulnerability is currently not being leveraged by attackers, they might soon reverse-engineer the hotfix and create a working exploit. As watchTowr researchers noted, “given SolarWinds’ past, in-the-wild exploitation is highly likely.” About CVE-2025-26399 “[CVE-2025-26399] exists within the AjaxProxy class. The issue results from the lack of proper validation … More →

    newswww.helpnetsecurity.comSep 24, 2025, 1:25 PM
  • SolarWinds fixed a critical flaw in its Web Help Desk software that could allow attackers to execute arbitrary commands on vulnerable systems. SolarWinds has released hot fixes to address a critical flaw, tracked as CVE-2025-26399 (CVSS score: 9.8), affecting its Web Help Desk software. An attacker could exploit the flaw to execute arbitrary commands on susceptible […]

    newssecurityaffairs.comSep 24, 2025, 11:50 AM
  • SolarWinds has released a third patch for essentially the same critical Java deserialization vulnerability in its Web Help Desk product. The original flaw was first patched in August 2024 with warnings from CISA that it had been exploited in the wild. “This vulnerability is a patch bypass of CVE-2024-28988, which in turn is a patch […]

    newswww.csoonline.comSep 23, 2025, 9:16 PM
  • CVE-2025-26399 is a patch bypass of CVE-2024-28988, which is a patch bypass of the exploited CVE-2024-28986.

    newswww.securityweek.comSep 23, 2025, 4:43 PM
  • No excerpt available.

    Mitigationwww.microsoft.comSep 23, 2025, 5:15 AM
  • No excerpt available.

    Mitigationwww.cisa.govSep 23, 2025, 5:15 AM
  • No excerpt available.

    Vendor Advisorywww.solarwinds.comSep 23, 2025, 5:15 AM
  • No excerpt available.

    Vendor Advisorydocumentation.solarwinds.comSep 23, 2025, 5:15 AM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence
  • CVE-2025-40553

    SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to…

    CVSS 9.8 · Critical
    7 mentions
  • CVE-2025-40551

    SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to…

    CVSS 9.8 · Critical
    KEV listed14 mentions
  • CVE-2024-28988

    SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an attacker to run commands on t…

    CVSS 9.8 · Critical
    12 mentions
  • CVE-2024-28986

    SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an attacker to run commands on t…

    CVSS 9.8 · Critical
    KEV listed33 mentions
  • CVE-2026-11536

    IBM WebSphere Application Server 9.0, and 8.5 is affected by a remote code execution vulnerability in the SOAP/JMX connector.

    CVSS 8.5 · High
    1 mention
  • CVE-2026-12118

    IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the deserialization of untrusted da…

    CVSS 9.8 · Critical
    1 mention