Junglewise Threat Intelligence

CVE-2025-26399: SolarWinds Web Help Desk deserialization RCE in AjaxProxy

CVE-2025-26399 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2026-03-09

Executive brief

SolarWinds Web Help Desk, a software platform used for managing IT service requests and support tickets, contains a critical security flaw. An attacker can exploit this vulnerability to gain full control over the server hosting the application without needing any login credentials. This could lead to the theft of sensitive support data, disruption of IT operations, or a complete takeover of the host system.

Technical details

SolarWinds Web Help Desk is vulnerable to an unauthenticated remote code execution (RCE) flaw due to the deserialization of untrusted data within the AjaxProxy component (CWE-502). This vulnerability represents a patch bypass of previous fixes for CVE-2024-28988 and CVE-2024-28986. An attacker can exploit this by sending a specially crafted request to the affected endpoint over the network, requiring no prior authentication or user interaction. Successful exploitation allows the attacker to execute arbitrary commands on the host machine with the privileges of the application. SolarWinds has released Web Help Desk 12.8.7 Hotfix 1 to address this issue.

Affected products

  • SolarWinds Web Help Desk Up to and including 12.8.6, 12.8.7 before Hotfix 1

Timeline

  • 2025-09-23: disclosed: Initial CVE assignment and publication by SolarWinds
  • 2026-02-06: advisory: Third-party advisory regarding active exploitation published by Microsoft
  • 2026-03-09: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) catalog

Related threats