The United States Cybersecurity and Infrastructure Security Agency (CISA) has added a critical security vulnerability in SolarWinds Web Help Desk (WHD) to the List of Known Exploitable Vulnerabilities (KEV).

The vulnerability, which is tracked as CVE-2025-40551 (CVSS score: 9.8), is an “untrusted data deserialization” vulnerability, which could open the way for remote code execution.
See also: Vulnerability in Apache Syncope allows user session hijacking
CISA stated: “SolarWinds Web Help Desk contains a vulnerability that could lead to remote code execution, allowing an attacker to execute commands on the host machine. The exploitation could be done without authentication.”
SolarWinds released updates for this vulnerability last week. Along with this, it also fixed other serious vulnerabilities: CVE-2025-40536 (CVSS score: 8.1), CVE-2025-40537 (CVSS score: 7.5), CVE-2025-40552 (CVSS score: 9.8), CVE-2025-40553 (CVSS score: 9.8), and CVE-2025-40554 (CVSS score: 9.8), in WHD version 2026.1.
At this time, there are no public reports on how the vulnerability is being used in attacks, who the targets might be, or the scale of these efforts. It is the latest indication of how quickly malicious actors are moving to exploit new vulnerabilities.
See also: OpenClaw flaw allows remote code execution

CISA: Adding SolarWinds and other vulnerabilities
In addition to the SolarWinds Web Help Desk vulnerability, CISA added three other vulnerabilities to the KEV List that have been exploited by cybercriminals:
– CVE-2019-19006 (CVSS score: 9.8) – An improper authentication in Sangoma FreePBX, which could potentially allow unauthorized users to bypass password authentication and gain access to services provided by the FreePBX administrator.
– CVE-2025-64328 (CVSS score: 8.6) – An OS command injection in Sangoma FreePBXcould allow command injection after authentication by a known user via the testconnection -> check_ssh_connect() function. This could lead to remote access to the system as the asterisk user.
– CVE-2021-39935 (CVSS score: 7.5/6.8) – A Server-Side Request Forgery (SSRF) vulnerability in GitLab Community and Enterprise, which could allow unauthorized external users to execute Server Side Requests via the CI Lint API.
See also: APT28 hackers exploit zero-day Microsoft Office vulnerability

It is worth noting that the CVE-2021-39935 exploit was identified by GreyNoise in March 2025. At that time, a coordinated increase in the exploitation of SSRF vulnerabilities across multiple platforms, including DotNetNuke, Zimbra Collaboration Suite, Broadcom VMware vCenter, ColumbiaSoft DocumentLocator, BerriAI LiteLLM, and Ivanti Connect Secure.
Federal agencies are required to patch the SolarWinds vulnerability (CVE-2025-40551) by February 6, 2026, and the remaining vulnerabilities by February 24, 2026.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
