← Back to browse · API

CVE-2025-26399

Severity
CRITICAL
CVSS
9.8
EPSS
0.8833
Risk score
95.12
CISA KEV
Yes
PoC
No
Published
2026-03-09
Modified
2026-03-09
First seen
2026-08-07
Aliases
EUVD-2025-30842, GHSA-VFRJ-F292-3F24
Products
SolarWinds:Web Help Desk, SolarWinds:Web Help Desk 12.8.7 and below
Sources
euvd EUVD-2025-30842
cisa.gov CVE-2025-26399

Description

SolarWinds Web Help Desk contain a deserialization of untrusted data vulnerability in AjaxProxy that could allow an attacker to run commands on the host machine.

References