Threat Intelligence / CVE / CVE-2025-26399

CVE-2025-26399

CISA KEV
CVSS 9.8 (CRITICAL) · EPSS 32.2% · Priority 9/10 · Published 2025-09-23

As of 2026-03-10, CVE-2025-26399 is a CVSS 9.8 (CRITICAL-severity) vulnerability. CISA KEV-listed (known exploited). EPSS exploitation probability 32.2%. Threadlinqs Intelligence tracks 0 threats exploiting it.

Last updated: 2026-03-10

SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. This vulnerability is a patch bypass of CVE-2024-28988, which in turn is a patch bypass of CVE-2024-28986.

CVSS v3 vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)

CWE-502

Exploitation status

CISA KEV-listed (known exploited)

References

Full detection coverage & IOCs for threats exploiting CVE-2025-26399 are available via the Threadlinqs MCP server (Purple tier). View plans →

← all vulnerabilities · Markdown version · Threadlinqs Intelligence

Enriched from CVE.org, NVD (this product uses the NVD API but is not endorsed or certified by the NVD), FIRST EPSS, CISA KEV, and GitHub Security Advisories.