SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability
SolarWinds · Web Help Desk
Date added (CISA)
2026-02-03
Remediation due
2026-02-06
Known ransomware use
Not indicated
Remediation priority
P2 — past CISA due date
Description
SolarWinds Web Help Desk contains a deserialization of untrusted data vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication.