SolarWinds has issued an urgent security update to address a severe vulnerability in its Web Help Desk software that could allow cybercriminals to execute malicious commands on affected systems without authentication.
## The Critical Flaw
The vulnerability, designated CVE-2025-26399, carries a maximum severity score of 9.8 out of 10. This flaw affects SolarWinds Web Help Desk version 12.8.7 and all earlier versions, potentially exposing thousands of organizations to cyberattacks.
The security issue stems from improper handling of untrusted data, specifically through a process called deserialization. This technical weakness allows attackers to remotely execute arbitrary code on vulnerable systems without needing login credentials.
## A Pattern of Patch Bypasses
What makes this situation particularly concerning is that CVE-2025-26399 represents the third attempt to fix the same underlying security problem:
– **August 2024**: SolarWinds initially patched CVE-2024-28986
– **Later in 2024**: Researchers discovered the first patch was incomplete, leading to CVE-2024-28988
– **September 2025**: The current fix addresses CVE-2025-26399, another bypass of previous patches
An anonymous security researcher working with Trend Micro’s Zero Day Initiative discovered and reported this latest vulnerability.
## Real-World Threat
While there’s no current evidence of active exploitation, the original vulnerability (CVE-2024-28986) was quickly added to the U.S. government’s list of Known Exploited Vulnerabilities, indicating it was being used in actual attacks.
Ryan Dewhurst, a cybersecurity expert at watchTowr, warned: “The original bug was actively exploited in the wild, and while we’re not yet aware of active exploitation of this latest patch bypass, history suggests it’s only a matter of time.”
## SolarWinds’ Troubled History
This latest security issue adds to SolarWinds’ challenging reputation following the devastating 2020 supply chain attack attributed to Russian intelligence services. That incident compromised multiple Western government agencies and highlighted the critical importance of software security.
## Immediate Action Required
Organizations using SolarWinds Web Help Desk must immediately update to version 12.8.7 HF1 to protect against potential attacks. Given the pattern of incomplete patches, IT administrators should prioritize this update and monitor for any additional security advisories.
The repeated need to patch the same vulnerability underscores the complexity of modern cybersecurity and the persistent nature of sophisticated threats targeting enterprise software.
