Unauthenticated deserialization enables remote code execution in SolarWinds Web Help Desk (CVE-2025-40553)
VulnCheck added this CVE to its known-exploited catalog today while a weaponized public exploit script is already available, so any internet-facing Web Help Desk instance still on 12.8.8 HF1 or below can be compromised without credentials by anyone who copies the script.
SolarWinds Web Help Desk deserializes untrusted data in a way that lets a remote attacker run commands on the host machine without any authentication. All versions up to and including 12.8.8 HF1 are affected, and a public exploit script from watchTowr is available.
Affected: SolarWinds Web Help Desk 12.8.8 HF1 and all previous versions
How to Test
Confirm the installed Web Help Desk version — anything at or below 12.8.8 HF1 is vulnerable. Review web server and application logs on the Web Help Desk host for unexpected POST requests and for command execution or child processes spawned by the Web Help Desk service, and treat any internet-exposed unpatched instance as potentially compromised.
How to Patch
Upgrade to SolarWinds Web Help Desk 12.8.8 HF2 or to the Web Help Desk 2026.1 release, both of which fix the deserialization flaw per the SolarWinds advisory. Until upgraded, restrict network access to the Web Help Desk web interface so it is not reachable from the internet.