CVE-2025-40536: SolarWinds Web Help Desk security-control bypass, actively exploited
The short version: SolarWinds Web Help Desk has a security-control bypass (CVE-2025-40536) that lets an unauthenticated attacker reach functionality that should be restricted. It's in CISA's KEV catalog — with an unusually short remediation window — and the fix is in the 2026.1 release. If you run an internet-facing Web Help Desk, confirm and patch. Steady hands, but move.
At a glance
| Fact | Detail |
|---|---|
| Our severity take | Moderate — in practice (see below) |
| CVSS v3.1 (NVD) | 9.8 — Critical · AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CVSS (SolarWinds, CNA) | 8.1 — High · AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 81.62% · 99.60th percentile (2026-07-17) |
| In CISA KEV? | Yes — remediation was due 2026-02-15 |
| Known exploited? | Yes — listed as a known-exploited vulnerability |
| Vulnerability type | CWE-693 protection-mechanism failure → unauthenticated access to restricted functionality |
| Requires authenticated session? | No — pre-authentication |
| Affected | SolarWinds Web Help Desk 12.8.8 HF1 and below |
| Fixed in | Web Help Desk 2026.1 |
What you need to know
The flaw is a failure in an access-control mechanism: an unauthenticated attacker can bypass a restriction and reach functionality that should require authentication or higher privilege.
- It's pre-authentication. No credentials needed to cross the control.
- The vendors disagree on difficulty — worth understanding. NVD scores 9.8; SolarWinds scores 8.1, differing mainly on attack complexity (AC:H in the vendor vector). Either way it's network-reachable with high impact.
- CISA moved fast. The KEV remediation window here was very tight, which signals confirmed exploitation and real urgency.
How serious we see it
Moderate — sitting between the two published scores, and here's why.
A security-control bypass that hands an unauthenticated attacker restricted functionality is frequently the first move in a longer chain — exactly the kind of foothold that precedes data access or a follow-on exploit. NVD's 9.8 treats the downstream impact as fully realized; SolarWinds' 8.1 factors in attack complexity. We land on High: KEV-listed and unauthenticated keep it serious, while the vendor's complexity note keeps us from automatically calling it Critical. The reassuring part is that it's bounded and fixed — a defined version line, a published release, and quick to confirm.
Recommendations
Straight from SolarWinds' advisory and CISA:
- Patch now. Upgrade Web Help Desk to 2026.1 or later.
- Restrict exposure. Keep Web Help Desk off the open internet where possible; limit it to trusted networks or a VPN.
- Hunt if you were exposed. Review access logs for use of the restricted functionality by unauthenticated requests.
- Rotate anything that may have been reached. If sensitive functionality or data was accessible, treat associated secrets as exposed.
- Confirm your exposure first. Verify whether you run an internet-facing Web Help Desk and which version.
How BreachRisk sees it
BreachRisk works this from the outside in. From little more than your domain it discovers internet-facing SolarWinds Web Help Desk, fingerprints the version, and flags exposure tied to KEV-listed, actively exploited vulnerabilities like this one, surfaced at the top because it's in KEV. We identify and flag the affected version; we don't exploit it. The continuous, attacker's-eye view means an exposed, unpatched Web Help Desk is already on your radar when the remediation clock is short.