CISA Adds Critical SolarWinds Web Help Desk Vulnerability to KEV Catalog
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) recently flagged a critical vulnerability in SolarWinds Web Help Desk (WHD), identified as CVE-2025-40551, and added it to its Known Exploited Vulnerabilities (KEV) catalog. This vulnerability has a CVSS score of 9.8 and involves untrusted data deserialization, which could enable remote code execution without requiring authentication. CISA’s alert emphasizes the potential for attackers to execute commands on affected host machines.
SolarWinds has responded by releasing fixes for this vulnerability as well as several others, including CVE-2025-40536 (CVSS score: 8.1), CVE-2025-40537 (CVSS score: 7.5), CVE-2025-40552 (CVSS score: 9.8), CVE-2025-40553 (CVSS score: 9.8), and CVE-2025-40554 (CVSS score: 9.8) in WHD version 2026.1. The rapid addition of CVE-2025-40551 to the KEV catalog illustrates the speed at which threat actors are moving to exploit newly disclosed vulnerabilities.
In addition to the SolarWinds vulnerability, CISA also added three other vulnerabilities to the KEV catalog. These include CVE-2019-19006, an improper authentication vulnerability in Sangoma FreePBX with a CVSS score of 9.8; CVE-2025-64328, an operating system command injection vulnerability in Sangoma FreePBX with a CVSS score of 8.6; and CVE-2021-39935, a server-side request forgery (SSRF) vulnerability in GitLab Community and Enterprise Editions with CVSS scores of 7.5/6.8.
Federal Civilian Executive Branch (FCEB) agencies are required to remediate CVE-2025-40551 by February 6, 2026, and the remaining vulnerabilities by February 24, 2026, as mandated by Binding Operational Directive (BOD) 22-01. This directive aims to reduce the significant risk posed by known exploited vulnerabilities.
Understanding the Risks
The exploitation of CVE-2021-39935 was previously highlighted by GreyNoise in March 2025, indicating a coordinated surge in the abuse of SSRF vulnerabilities across multiple platforms. This trend underscores the importance of vigilance in monitoring and securing systems against known vulnerabilities.
Organizations using SolarWinds Web Help Desk and the affected Sangoma FreePBX should prioritize applying the latest security patches to mitigate the risk of exploitation. The urgency of addressing these vulnerabilities is amplified by the lack of public reports detailing how they are being weaponized in attacks.
Key Takeaways
- Update SolarWinds Web Help Desk to version 2026.1 to mitigate the CVE-2025-40551 vulnerability.
- Ensure that all relevant patches for CVE-2025-40536, CVE-2025-40537, CVE-2025-40552, CVE-2025-40553, and CVE-2025-40554 are applied promptly.
- Monitor for any unusual activity or unauthorized access attempts on systems using affected software.
- Review and enhance security protocols to prevent exploitation of known vulnerabilities.
- Stay informed about updates from CISA regarding newly added vulnerabilities and remediation deadlines.
Key Terms & Concepts
- CVE: In this article, CVE refers to the Common Vulnerabilities and Exposures system that provides a reference-method for publicly known information security vulnerabilities.
- CVSS: CVSS stands for Common Vulnerability Scoring System, which assigns a score to vulnerabilities based on their severity and impact.
- Remote Code Execution: Remote Code Execution is a type of vulnerability that allows an attacker to execute commands on a remote machine.
- Deserialization: Deserialization is the process of converting data from a format suitable for storage or transmission back into a usable object, which can introduce security risks if not handled properly.
- Binding Operational Directive (BOD): BOD is a directive issued by CISA that mandates federal agencies to address significant cybersecurity risks.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.