Executive Summary
In September 2025, SolarWinds disclosed a critical security vulnerability (CVE-2025-26399) in its Web Help Desk (WHD) software, affecting version 12.8.7 and prior. This flaw—stemming from unsafe deserialization in the AjaxProxy component—permits unauthenticated attackers to achieve remote code execution (RCE) on affected servers. The issue represents a patch bypass for earlier vulnerabilities (CVE-2024-28986, CVE-2024-28988), demonstrating persistent weaknesses in the remediation process. While there are no documented exploitations as of publication, previous flaws in this component were added to CISA’s Known Exploited Vulnerabilities catalog, underscoring risk to organizations reliant on WHD for ticketing and IT asset management.
This incident underscores the enduring challenge of patch bypasses, where subsequent hotfixes fail to fully resolve underlying flaws, leading to repeated exposures. Weaknesses in serialization logic and high-value IT management software are a favored target for attackers seeking lateral movement, privilege escalation, or supply chain compromise.
Why This Matters Now
This vulnerability exemplifies the critical need for effective patch management and deep technical validation post-remediation—especially for tools with broad enterprise access like Web Help Desk. Unauthenticated RCEs offer threat actors a direct line to compromise infrastructure, and repeated patch bypasses indicate latent risks that could be leveraged in future campaigns.
Attack Path Analysis
An unauthenticated attacker exploited a critical RCE flaw in SolarWinds Web Help Desk via unsafe deserialization, gaining initial access to the host system. Upon access, the attacker potentially elevated privileges using command execution on the underlying OS. From there, lateral movement to adjacent systems or services within the environment was possible, leveraging unsecured east-west communications. The attacker established command and control, likely via outbound connections to remote infrastructure. Sensitive data could be exfiltrated over unmonitored egress channels. Finally, the attacker could have disrupted operations, accessed or destroyed data, or leveraged persistence mechanisms for further impact.
Kill Chain Progression
Initial Compromise
Description
Exploitation of the SolarWinds Web Help Desk RCE (CVE-2025-26399) vulnerability allowed unauthenticated remote code execution on the target host.
Related CVEs
CVE-2025-26399
CVSS 9.8An unauthenticated remote code execution vulnerability in SolarWinds Web Help Desk's AjaxProxy component due to unsafe deserialization handling.
Affected Products:
SolarWinds Web Help Desk – 12.8.7
Exploit Status:
no public exploitCVE-2024-28988
CVSS 9.8A Java deserialization remote code execution vulnerability in SolarWinds Web Help Desk allowing attackers to execute arbitrary commands on the host machine.
Affected Products:
SolarWinds Web Help Desk – 12.8.3
Exploit Status:
no public exploitCVE-2024-28986
CVSS 9.8A Java deserialization remote code execution vulnerability in SolarWinds Web Help Desk that could allow attackers to run commands on the host machine.
Affected Products:
SolarWinds Web Help Desk – 12.8.3 and earlier
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Exploitation for Client Execution
Access Token Manipulation
Process Injection
Network Sniffing
Valid Accounts
Exploitation for Defense Evasion
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Security of Public-Facing Web Applications
Control ID: 6.2.3
NYDFS 23 NYCRR 500 – Cybersecurity Policy and Access Controls
Control ID: 500.03, 500.07
DORA – ICT Risk Management and Vulnerability Handling
Control ID: Art. 10, Art. 21
NIS2 Directive – Incident Handling and Vulnerability Disclosure
Control ID: Art. 21(2)(d), Art. 23
CISA Zero Trust Maturity Model 2.0 – Application Security - Patch Management
Control ID: Pillar: Applications, Level: Initial
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Information Technology/IT
Critical RCE vulnerability in SolarWinds Web Help Desk exposes IT service providers to unauthenticated remote attacks, requiring immediate patching.
Computer Software/Engineering
Software vulnerability demonstrates deserialization flaws affecting help desk platforms, creating supply chain risks for software development organizations using SolarWinds.
Financial Services
Third patch bypass highlights persistent attack surface in ticketing systems managing sensitive financial data, violating regulatory compliance requirements.
Health Care / Life Sciences
Healthcare organizations using Web Help Desk face HIPAA compliance violations due to potential unauthorized access through unauthenticated RCE exploitation.
Sources
- SolarWinds releases third patch to fix Web Help Desk RCE bughttps://www.bleepingcomputer.com/news/security/solarwinds-releases-third-patch-to-fix-web-help-desk-rce-bug/Verified
- WHD 12.8.7 Hotfix 1 Release Noteshttps://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_12-8-7-hotfix-1_release_notes.htmVerified
- WHD 12.8.3 Hotfix 3 Release Noteshttps://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_12-8-3-hotfix-3_release_notes.htmVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Network segmentation, east-west traffic controls, and robust egress policy enforcement through the CNSF would have significantly limited attack propagation, detected anomalous behaviors, and reduced the attacker's ability to execute key kill chain phases.
Control: Cloud Firewall (ACF)
Mitigation: Blocked unauthorized inbound traffic attempting exploitation.
Control: Threat Detection & Anomaly Response
Mitigation: Detected suspicious privilege escalation activities.
Control: Zero Trust Segmentation
Mitigation: Prevented unauthorized east-west lateral movement.
Control: Egress Security & Policy Enforcement
Mitigation: Blocked or detected unauthorized outbound C2 traffic.
Control: Encrypted Traffic (HPE)
Mitigation: Prevented data leakage through unencrypted channels.
Detected and blocked malicious payloads or destructive activity in real time.
Impact at a Glance
Affected Business Functions
- IT Support Services
- Help Desk Operations
Estimated downtime: 3 days
Estimated loss: $50,000
Potential exposure of sensitive IT support tickets and client information due to unauthorized access.
Recommended Actions
Key Takeaways & Next Steps
- • Deploy perimeter cloud firewalls and tighten inbound policies to prevent exploit delivery to vulnerable applications.
- • Implement Zero Trust Segmentation to strictly limit east-west traffic and block unauthorized lateral movement opportunities.
- • Enforce strong egress controls with FQDN and protocol filtering to prevent unauthorized C2 and data exfiltration.
- • Adopt continuous threat detection and anomaly response to quickly identify and respond to privilege escalation or suspicious activity.
- • Ensure all sensitive data in transit is encrypted and monitor for attempts at policy circumvention or unencrypted connections.



