By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: CISA Adds Actively Exploited SolarWinds Web Help Desk RCE to KEV Catalog
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > CISA Adds Actively Exploited SolarWinds Web Help Desk RCE to KEV Catalog
Computing

CISA Adds Actively Exploited SolarWinds Web Help Desk RCE to KEV Catalog

News Room
Last updated: 2026/02/04 at 2:28 AM
News Room Published 4 February 2026
Share
CISA Adds Actively Exploited SolarWinds Web Help Desk RCE to KEV Catalog
SHARE

Ravie LakshmananFeb 04, 2026Software Security / Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a critical security flaw impacting SolarWinds Web Help Desk (WHD) to its Known Exploited Vulnerabilities (KEV) catalog, flagging it as actively exploited in attacks.

The vulnerability, tracked as CVE-2025-40551 (CVSS score: 9.8), is a untrusted data deserialization vulnerability that could pave the way for remote code execution.

“SolarWinds Web Help Desk contains a deserialization of untrusted data vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine,” CISA said. “This could be exploited without authentication.”

SolarWinds issued fixes for the flaw last week, along with CVE-2025-40536 (CVSS score: 8.1), CVE-2025-40537 (CVSS score: 7.5), CVE-2025-40552 (CVSS score: 9.8), CVE-2025-40553 (CVSS score: 9.8), and CVE-2025-40554 (CVSS score: 9.8), in WHD version 2026.1.

There are currently no public reports about how the vulnerability is being weaponized in attacks, who may be the targets, or the scale of such efforts. It’s the latest illustration of how quickly threat actors are moving to exploit newly disclosed flaws.

Also added to the KEV catalog are three other vulnerabilities –

  • CVE-2019-19006 (CVSS score: 9.8) – An improper authentication vulnerability in Sangoma FreePBX that potentially allows unauthorized users to bypass password authentication and access services provided by the FreePBX administrator
  • CVE-2025-64328 (CVSS score: 8.6) – An operating system command injection vulnerability in Sangoma FreePBX that could allow for a post-authentication command injection by an authenticated known user via the testconnection -> check_ssh_connect() function and potentially obtain remote access to the system as an asterisk user
  • CVE-2021-39935 (CVSS score: 7.5/6.8) – A server-side request forgery (SSRF) vulnerability in GitLab Community and Enterprise Editions that could allow unauthorized external users to perform Server Side Requests via the CI Lint API

It’s worth noting that the exploitation of CVE-2021-39935 was highlighted by GreyNoise in March 2025, as part of a coordinated surge in the abuse of SSRF vulnerabilities in multiple platforms, including DotNetNuke, Zimbra Collaboration Suite, Broadcom VMware vCenter, ColumbiaSoft DocumentLocator, BerriAI LiteLLM, and Ivanti Connect Secure.

Federal Civilian Executive Branch (FCEB) agencies are required to fix CVE-2025-40551 by February 6, 2026, and the rest by February 24, 2026, pursuant to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Mozilla Adds Option to Disable New AI Features Coming to Firefox Browser Mozilla Adds Option to Disable New AI Features Coming to Firefox Browser
Next Article Fairphone 6 review: cheaper, repairable and longer-lasting Android Fairphone 6 review: cheaper, repairable and longer-lasting Android
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Best Beats deal: Save  on Beats Studio Buds+
Best Beats deal: Save $70 on Beats Studio Buds+
News
AMD Expands FPGA Offerings With Mid-Range Kintex UltraScale+ Gen 2
AMD Expands FPGA Offerings With Mid-Range Kintex UltraScale+ Gen 2
Computing
ChatGPT is down for many users in major OpenAI outage – 9to5Mac
ChatGPT is down for many users in major OpenAI outage – 9to5Mac
News
Firefox Just Unveiled The Only AI Setting Every Browser Needs – BGR
Firefox Just Unveiled The Only AI Setting Every Browser Needs – BGR
News

You Might also Like

AMD Expands FPGA Offerings With Mid-Range Kintex UltraScale+ Gen 2
Computing

AMD Expands FPGA Offerings With Mid-Range Kintex UltraScale+ Gen 2

1 Min Read
XPeng Reportedly Merges Autonomous Driving and Smart Cockpit Units Into New General AI Center · TechNode
Computing

XPeng Reportedly Merges Autonomous Driving and Smart Cockpit Units Into New General AI Center · TechNode

1 Min Read
Sprout Social vs Hootsuite: Tested & Compared
Computing

Sprout Social vs Hootsuite: Tested & Compared

11 Min Read
Microsoft Warns Python Infostealers Target macOS via Fake Ads and Installers
Computing

Microsoft Warns Python Infostealers Target macOS via Fake Ads and Installers

3 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?