peter bassill · operator
$ cve CVE-2025-40553 JSON

CVE-2025-40553

9.8
CRITICAL · CVSS 3.1 · EPSS 68% (pctl 99)

Patch early

EPSS 68% — above the 10% action threshold.

Description

SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS67.98% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-502
On CISA KEVno
Public exploitnone known
Published2026-01-28
Last modified2026-06-17

Affected (1)

VendorProduct
solarwindsweb help desk

References

→ the Explorer  ·  watch your stack  ·  NVD