HomeSecurityCISA adds SolarWinds WHD vulnerability to KEV List

CISA adds SolarWinds WHD vulnerability to KEV List

The United States Cybersecurity and Infrastructure Security Agency (CISA) has added a critical security vulnerability in SolarWinds Web Help Desk (WHD) to the List of Known Exploitable Vulnerabilities (KEV).

CISA SolarWinds

The vulnerability, which is tracked as CVE-2025-40551 (CVSS score: 9.8), is an “untrusted data deserialization” vulnerability, which could open the way for remote code execution.

See also: Vulnerability in Apache Syncope allows user session hijacking

CISA stated: “SolarWinds Web Help Desk contains a vulnerability that could lead to remote code execution, allowing an attacker to execute commands on the host machine. The exploitation could be done without authentication.”

SolarWinds released updates for this vulnerability last week. Along with this, it also fixed other serious vulnerabilities: CVE-2025-40536 (CVSS score: 8.1), CVE-2025-40537 (CVSS score: 7.5), CVE-2025-40552 (CVSS score: 9.8), CVE-2025-40553 (CVSS score: 9.8), and CVE-2025-40554 (CVSS score: 9.8), in WHD version 2026.1.

At this time, there are no public reports on how the vulnerability is being used in attacks, who the targets might be, or the scale of these efforts. It is the latest indication of how quickly malicious actors are moving to exploit new vulnerabilities.

See also: OpenClaw flaw allows remote code execution

CISA adds SolarWinds WHD vulnerability to KEV List

CISA: Adding SolarWinds and other vulnerabilities

In addition to the SolarWinds Web Help Desk vulnerability, CISA added three other vulnerabilities to the KEV List that have been exploited by cybercriminals:

– CVE-2019-19006 (CVSS score: 9.8) – An improper authentication in Sangoma FreePBX, which could potentially allow unauthorized users to bypass password authentication and gain access to services provided by the FreePBX administrator.

– CVE-2025-64328 (CVSS score: 8.6) – An OS command injection in Sangoma FreePBXcould allow command injection after authentication by a known user via the testconnection -> check_ssh_connect() function. This could lead to remote access to the system as the asterisk user.

– CVE-2021-39935 (CVSS score: 7.5/6.8) – A Server-Side Request Forgery (SSRF) vulnerability in GitLab Community and Enterprise, which could allow unauthorized external users to execute Server Side Requests via the CI Lint API.

See also: APT28 hackers exploit zero-day Microsoft Office vulnerability

CISA adds SolarWinds WHD vulnerability to KEV List

It is worth noting that the CVE-2021-39935 exploit was identified by GreyNoise in March 2025. At that time, a coordinated increase in the exploitation of SSRF vulnerabilities across multiple platforms, including DotNetNuke, Zimbra Collaboration Suite, Broadcom VMware vCenter, ColumbiaSoft DocumentLocator, BerriAI LiteLLM, and Ivanti Connect Secure.

Federal agencies are required to patch the SolarWinds vulnerability (CVE-2025-40551) by February 6, 2026, and the remaining vulnerabilities by February 24, 2026.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS