SolarWinds Web Help Desk is experiencing active exploitation through a chain of vulnerabilities including two critical zero-days (CVE-2025-40551 and CVE-2025-40536) combined with an older flaw from September 2025. Attackers are achieving remote code execution through Java deserialization vulnerabilities in the Apache Tomcat-based application. Security researchers at Huntress confirmed the attack chain after analyzing customer incidents, revealing sophisticated post-compromise techniques including Velociraptor C2 and Cloudflared tunnels. All WHD versions prior to 12.8.7 HF1 are vulnerable, affecting an estimated 300,000 customers who need to urgently upgrade to WHD 2026.1.

3m read timeFrom csoonline.com
Post cover image
3 Impressions