Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»SolarWinds Patches Critical Web Help Desk Vulnerabilities
    Cybersecurity

    SolarWinds Patches Critical Web Help Desk Vulnerabilities

    adminBy adminJanuary 29, 2026No Comments3 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    SolarWinds patches vulnerability
    Share
    Facebook Twitter LinkedIn Pinterest Email

    SolarWinds on Wednesday announced patches for six vulnerabilities in the Web Help Desk product, including four critical-severity bugs.

    First in line is CVE-2025-40551 (CVSS score of 9.8), a critical flaw described as an untrusted data deserialization issue that could lead to remote code execution (RCE) without authentication.

    According to Horizon3.ai, which discovered and reported the defect, CVE-2025-40551 exists in AjaxProxy functionality, where requests destined for other functions are improperly sanitized, and a blocklist function can be bypassed by including allowed terms early in a JSON payload.

    The method, Horizon3.ai explains, has been used in the exploitation of CVE-2024-28986 and subsequent bypasses (tracked as CVE-2024-28988 and CVE-2025-26399), which were also rooted in the AjaxProxy functionality.

    The remaining three critical vulnerabilities, CVE-2025-40552, CVE-2025-40553, and CVE-2025-40554 (CVSS score of 9.8), were discovered and reported by WatchTowr.

    CVE-2025-40553 is another untrusted data deserialization flaw that could lead to unauthenticated RCE, but no technical details have been released.

    Advertisement. Scroll to continue reading.

    CVE-2025-40552 and CVE-2025-40554 are described as authentication bypass defects that could allow remote attackers to execute or invoke specific actions or methods. The critical severity of the issues suggests that both could be exploited for RCE, Rapid7 notes.

    The remaining two Web Help Desk issues addressed on Wednesday are high-severity vulnerabilities: a security control bypass issue (CVE-2025-40536) and a hardcoded credentials bug (CVE-2025-40537). Both were discovered by Horizon3.ai.

    CVE-2025-40536, the cybersecurity firm explains, exists because a function that verifies CSRF tokens and validates request query parameters can be bypassed via bogus URI parameters to access certain restricted functionality.

    Successful exploitation of the issue allows an attacker to successfully create a valid AjaxProxy instance, which could then be abused to trigger CVE-2025-40551 and achieve RCE, Horizon3.ai says.

    CVE-2025-40537, the company notes, exists because, upon initialization, Web Help Desk creates a client account with the default username and password of ‘client’, for demo purposes.

    “While this account appears to be limited in its access rights in some production environments, we’ve come across cases where this account is still associated with the default tech account and allows anyone logging in with this ‘client’ user account to switch to the administrator account,” Horizon3.ai explains.

    All six vulnerabilities have been addressed with the release of Web Help Desk version 2026.1. Although none of these bugs has been flagged as exploited in the wild, organizations are advised to update their instances as soon as possible.

    Related: Fortinet Patches Exploited FortiCloud SSO Authentication Bypass

    Related: High-Severity Remote Code Execution Vulnerability Patched in OpenSSL

    Related: Microsoft Patches Office Zero-Day Likely Exploited in Targeted Attacks

    Related: Atlassian, GitLab, Zoom Release Security Patches

    Critical Desk Patches SolarWinds Vulnerabilities Web
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleCritical Telnet Server Flaw Exposes Forgotten Attack Surface
    Next Article Netscout boosts network observability with Wi-Fi 7 monitoring, certificate lifecycle tracking
    admin
    • Website

    Related Posts

    Apple account change alerts abused to send phishing emails

    April 19, 2026

    Social media bans might steer kids into riskier corners of the internet

    April 19, 2026

    Vercel confirms breach as hackers claim to be selling stolen data

    April 19, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    The best robot vacuum in Australia: reliable, effective, effort-free automated cleaners

    April 20, 2026

    Monitor spec sheets hide the one thing that actually decides whether a display feels premium

    April 19, 2026

    Apple account change alerts abused to send phishing emails

    April 19, 2026

    Apple AirPods Pro 3 review: A masterclass in sound, a lesson in lock-in

    April 19, 2026
    Categories
    • Blogging (65)
    • Cybersecurity (1,403)
    • Privacy & Online Earning (172)
    • SEO & Digital Marketing (850)
    • Tech Tools & Mobile / Apps (1,683)
    • WiFi / Internet & Networking (232)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    The best robot vacuum in Australia: reliable, effective, effort-free automated cleaners

    April 20, 2026

    Monitor spec sheets hide the one thing that actually decides whether a display feels premium

    April 19, 2026

    Apple account change alerts abused to send phishing emails

    April 19, 2026
    Most Popular
    • The best robot vacuum in Australia: reliable, effective, effort-free automated cleaners
    • Monitor spec sheets hide the one thing that actually decides whether a display feels premium
    • Apple account change alerts abused to send phishing emails
    • Apple AirPods Pro 3 review: A masterclass in sound, a lesson in lock-in
    • Samsung Galaxy S23 Ultra versus vivo X300 Ultra
    • Here’s How Netflix Plans to Add TikTok-Style Videos to Its Mobile App
    • Social media bans might steer kids into riskier corners of the internet
    • eSIM was supposed to replace SIM cards, but carriers turned it into a trap
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.