Critical severity9.8NVD Advisory· Published Jan 28, 2026· Updated Jun 17, 2026
CVE-2025-40553
CVE-2025-40553
Description
SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:solarwinds:web_help_desk:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:solarwinds:web_help_desk:*:*:*:*:*:*:*:*range: <2026.1
- (no CPE)
- (no CPE)range: 12.8.8 HF1 and below
Patches
Vulnerability mechanics
References
3- www.solarwinds.com/trust-center/security-advisories/CVE-2025-40553nvdVendor Advisory
- documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_2026-1_release_notes.htmnvdRelease Notes
- github.com/watchtowrlabs/watchTowr-vs-SolarWinds-WebHelpDesk-CVE-2025-40552-CVE-2025-40553/blob/main/watchTowr-vs-SolarWinds-WebHelpDesk-CVE-2025-40552-CVE-2025-40553.pynvd
News mentions
2- 16th March – Threat Intelligence ReportCheck Point Research · Mar 16, 2026
- Buy A Help Desk, Bundle A Remote Access Solution? (SolarWinds Web Help Desk Pre-Auth RCE Chain(s))watchTowr Labs · Feb 25, 2026