CVE-2025-26399
SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. This vulnerability is a patch bypass of CVE-2024-28988, which in turn is a patch bypass of CVE-2024-28986.
Vendor
Product
CWE
Yayın Tarihi
2025-09-23 05:15:35
Güncelleme
2026-03-10 13:11:15
Source Identifier
psirt@solarwinds.com
KEV Date Added
2026-03-09
Kategoriler
Referanslar
https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_12-8-7-hotfix-1_release_notes.htm
https://www.solarwinds.com/trust-center/security-advisories/CVE-2025-26399
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-26399
https://www.microsoft.com/en-us/security/blog/2026/02/06/active-exploitation-solarwinds-web-help-desk/