SolarWinds Web Help Desk is experiencing active exploitation through a chain of vulnerabilities including two critical zero-days (CVE-2025-40551 and CVE-2025-40536) combined with an older flaw from September 2025. Attackers are achieving remote code execution through Java deserialization vulnerabilities in the Apache Tomcat-based application. Security researchers at Huntress confirmed the attack chain after analyzing customer incidents, revealing sophisticated post-compromise techniques including Velociraptor C2 and Cloudflared tunnels. All WHD versions prior to 12.8.7 HF1 are vulnerable, affecting an estimated 300,000 customers who need to urgently upgrade to WHD 2026.1.
3 Impressions