Threat Intelligence / CVE / CVE-2025-40554
CVE-2025-40554
RansomwareAs of 2026-02-03, CVE-2025-40554 is a CVSS 9.8 (CRITICAL-severity) vulnerability. EPSS exploitation probability 6.1%. Threadlinqs Intelligence tracks 1 threat exploiting it.
Last updated: 2026-02-03
SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that, if exploited, could allow an attacker to invoke specific actions within Web Help Desk.
CVSS v3 vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
CWE-1390
Threats tracking this CVE
- SolarWinds Web Help Desk Pre-Auth RCE Chain (CVE-2025-40552, CVE-2025-40553, CVE-2025-40554) — CRITICAL
References
- https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_2026-1_release_notes.htm
- https://www.solarwinds.com/trust-center/security-advisories/CVE-2025-40554
Full detection coverage & IOCs for threats exploiting CVE-2025-40554 are available via the Threadlinqs MCP server (Purple tier). View plans →
← all vulnerabilities · Markdown version · Threadlinqs Intelligence
Enriched from CVE.org, NVD (this product uses the NVD API but is not endorsed or certified by the NVD), FIRST EPSS, CISA KEV, and GitHub Security Advisories.