High severity8.1CISA KEVNVD Advisory· Published Jan 28, 2026· Updated Jun 17, 2026
CVE-2025-40536
CVE-2025-40536
Description
SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could allow an unauthenticated attacker to gain access to certain restricted functionality.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:solarwinds:web_help_desk:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:solarwinds:web_help_desk:*:*:*:*:*:*:*:*range: <2026.1
- (no CPE)range: 12.8.8 HF1 and below
Patches
Vulnerability mechanics
References
4- www.huntress.com/blog/active-exploitation-solarwinds-web-help-desk-cve-2025-26399nvdThird Party Advisory
- www.solarwinds.com/trust-center/security-advisories/CVE-2025-40536nvdVendor Advisory
- documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_2026-1_release_notes.htmnvdRelease Notes
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
0No linked articles in our index yet.