Skip to content

SolarWinds warns over pre-auth RCE help desk bug

Expect this to get exploited - like the bug before it...

SolarWinds warns over pre-auth RCE help desk bug
It's whac-a-mole over at SolarWinds... Credit: https://unsplash.com/@laralone

SolarWinds says its web help desk software can be remotely exploited by an unauthenticated attacker – issuing a critical CVSS 9.8 alert for a new vulnerability, CVE-2025-26399; a bypass of a previously exploited bug. 

“This vulnerability is a patch bypass of CVE-2024-28988, which in turn is a patch bypass of CVE-2024-28986,” Solarwinds admitted today.

This content is for members only

Subscribe
Add The Stack on Google