CVE-2025-40536 is a security control bypass vulnerability in SolarWinds Web Help Desk that allows unauthenticated attackers to gain access to restricted functionality. This vulnerability is being actively exploited in the wild against internet-facing WHD instances for initial access and lateral movement.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2026-01-28
Added to CISA KEV: 2026-02-12 15 DAYS BETWEEN CVE AND KEV
Here's a breakdown of what is known about its exploitation:
The Microsoft Defender Research Team observed a multiāstage intrusion where threat actors exploited internetāexposed SolarWinds Web Help Desk (WHD) instances to get an initial foothold and then laterally moved towards other high-value assets within the organization. However, we have not yet confirmeā¦
SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could allow an unauthenticated attacker to gain access to certain restricted functionality.Description. SolarWinds Web Help Desk was found to be susceptible to a security control bypassā¦
Microsoft has revealed that it observed a multiāstage intrusion that involved the threat actors exploiting internetāexposed SolarWinds Web Help Desk (WHD) instances to obtain initial access and move laterally across the organization's network to other high-value assets. That said, the Microsoft Defeā¦
For the benefit of the cybersecurity community and network defendersāand to help every organization better manage vulnerabilities and keep pace with threat activityāCISA maintains the authoritative source of vulnerabilities that have been exploited in the wild. Organizations should use the KEV catalā¦
CVE-2025-40536 is an authentication bypass vulnerability in SolarWinds Web Help Desk allowing unauthenticated attackers to access restricted ...