S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Aug 30, 2026

CVE-2025-26399 Scanner

CVE-2025-26399 Scanner - Deserialization of Untrusted Data vulnerability in SolarWinds Web Help Desk

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.8k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2025-26399
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. This vulnerability is a patch bypass of CVE-2024-28988, which in turn is a patch bypass of CVE-2024-28986.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Web Help Deskby SolarWinds
12.8.7 and below
Updated Sep 9, 2026View on NVD →
Detail

SolarWinds Web Help Desk is used by IT professionals for ticketing, asset management, and change management tasks. This system is popular in enterprise environments due to its robust features in managing IT service requests. It helps organizations streamline their IT support process through better organization and tracking of tickets. The Web Help Desk is often deployed in various enterprises for centralized help desk functionalities. It integrates with other network management tools to provide comprehensive IT solutions. Regular updates are essential to prevent vulnerabilities from compromising the software's security.

The vulnerability detected in this product is the deserialization of untrusted data. An attacker can exploit this vulnerability to execute arbitrary code on the affected system. This poses a significant risk as it enables unauthorized access to system commands and data. The vulnerability can lead to full system compromise, affecting the integrity and confidentiality of the data managed by the system. It does not require special privileges or authentication, making it an even greater threat. Organizations using affected versions should take immediate action to mitigate the risk.

The vulnerability specifically involves the AjaxProxy deserialization mechanism. Attackers can inject malicious deserialization payloads to achieve remote code execution. The issue exists in the endpoint that handles deserialization processes within Web Help Desk. By sending carefully crafted requests, attackers can exploit the vulnerability without user interaction. The vulnerable parameter is likely related to the way objects are handled and validated during deserialization operations. Ensuring that the latest secure versions are applied can prevent this attack vector.

Exploitation of this vulnerability may lead to several effects if an attacker successfully takes control. They can access sensitive data, alter system configurations, and run arbitrary commands which could disrupt business operations. The vulnerability's nature makes it possible for attackers to deploy ransomware or other malicious software. It poses a risk of data exfiltration and potential data loss. Implementing patched versions and employing strict access control measures can mitigate the potential effects. Ensuring secure deserialization practices is crucial to enhance security resilience.

REFERENCES

Solution Advice
  • Update SolarWinds Web Help Desk to version 12.8.7 or later to mitigate the vulnerability.
  • Utilize network segmentation to limit access to Web Help Desk instances.
  • Implement intrusion detection systems to detect potential exploitation attempts.
  • Regularly monitor logs for suspicious activities related to deserialization attacks.
  • Ensure that all deserialization processes use secure coding practices to prevent similar vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2025-26399 Scanner - Deserialization of Untrusted Data vulnerability in SolarWinds Web Help Desk | S4E