>> All posts

CVE-2025-40536: SolarWinds Web Help Desk security-control bypass, actively exploited

The short version: SolarWinds Web Help Desk has a security-control bypass (CVE-2025-40536) that lets an unauthenticated attacker reach functionality that should be restricted. It's in CISA's KEV catalog — with an unusually short remediation window — and the fix is in the 2026.1 release. If you run an internet-facing Web Help Desk, confirm and patch. Steady hands, but move.

At a glance

FactDetail
Our severity takeModerate — in practice (see below)
CVSS v3.1 (NVD)9.8 — Critical · AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS (SolarWinds, CNA)8.1 — High · AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS81.62% · 99.60th percentile (2026-07-17)
In CISA KEV?Yes — remediation was due 2026-02-15
Known exploited?Yes — listed as a known-exploited vulnerability
Vulnerability typeCWE-693 protection-mechanism failure → unauthenticated access to restricted functionality
Requires authenticated session?No — pre-authentication
AffectedSolarWinds Web Help Desk 12.8.8 HF1 and below
Fixed inWeb Help Desk 2026.1

What you need to know

The flaw is a failure in an access-control mechanism: an unauthenticated attacker can bypass a restriction and reach functionality that should require authentication or higher privilege.

  • It's pre-authentication. No credentials needed to cross the control.
  • The vendors disagree on difficulty — worth understanding. NVD scores 9.8; SolarWinds scores 8.1, differing mainly on attack complexity (AC:H in the vendor vector). Either way it's network-reachable with high impact.
  • CISA moved fast. The KEV remediation window here was very tight, which signals confirmed exploitation and real urgency.

How serious we see it

Moderate — sitting between the two published scores, and here's why.

A security-control bypass that hands an unauthenticated attacker restricted functionality is frequently the first move in a longer chain — exactly the kind of foothold that precedes data access or a follow-on exploit. NVD's 9.8 treats the downstream impact as fully realized; SolarWinds' 8.1 factors in attack complexity. We land on High: KEV-listed and unauthenticated keep it serious, while the vendor's complexity note keeps us from automatically calling it Critical. The reassuring part is that it's bounded and fixed — a defined version line, a published release, and quick to confirm.

Recommendations

Straight from SolarWinds' advisory and CISA:

  1. Patch now. Upgrade Web Help Desk to 2026.1 or later.
  2. Restrict exposure. Keep Web Help Desk off the open internet where possible; limit it to trusted networks or a VPN.
  3. Hunt if you were exposed. Review access logs for use of the restricted functionality by unauthenticated requests.
  4. Rotate anything that may have been reached. If sensitive functionality or data was accessible, treat associated secrets as exposed.
  5. Confirm your exposure first. Verify whether you run an internet-facing Web Help Desk and which version.

How BreachRisk sees it

BreachRisk works this from the outside in. From little more than your domain it discovers internet-facing SolarWinds Web Help Desk, fingerprints the version, and flags exposure tied to KEV-listed, actively exploited vulnerabilities like this one, surfaced at the top because it's in KEV. We identify and flag the affected version; we don't exploit it. The continuous, attacker's-eye view means an exposed, unpatched Web Help Desk is already on your radar when the remediation clock is short.

References

See your cyber risk, proven.