Threat Intelligence / CVE / CVE-2025-26399

CVE-2025-26399

CISA KEV
CVSS 9.8 (CRITICAL) · EPSS 32.2% · Published 2025-09-23

SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. This vulnerability is a patch bypass of CVE-2024-28988, which in turn is a patch bypass of CVE-2024-28986.

CVSS v3 vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)

CWE-502

Threats tracking this CVE

References

Full detection coverage & IOCs for threats exploiting CVE-2025-26399 are available via the Threadlinqs MCP server (Purple tier). View plans →

Markdown version · Threadlinqs Intelligence