Known vulnerability record

CVE-2025-26399

SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability

Stable IDcve:CVE-2025-26399Last updatedLast verifiedLegacy review pendingProvenanceCISA KEV + CVE record + EPSS

SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability

SolarWinds Web Help Desk contain a deserialization of untrusted data vulnerability in AjaxProxy that could allow an attacker to run commands on the host machine.

Keep the signals separate

CVSS severitycriticalScore 9.8 · source SolarWinds
EPSS probability88.3%Probability of exploitation in the next 30 days; not severity
CISA KEVKnown exploitedAdded 2026-03-09
Ransomware useknownPreserved as known / unknown, not a truthy default

Dates and provenance

CVE published
2025-09-23
CVE modified
2026-08-04
KEV date added
2026-03-09
Dataset fetched
2026-08-21T03:54:59.577Z

Original records

Version history: normalized permanent page created 2026-08-20. Machine-enriched fields remain source-attributed.