CVE-2025-40553 is a critical untrusted data deserialization vulnerability affecting SolarWinds Web Help Desk, allowing unauthenticated remote code execution. With a CVSS score of 9.8, this flaw enables attackers to fully compromise the host system without prior authentication. While there is no confirmed active exploitation, the vulnerability has garnered significant community discussion and media attention, indicating high awareness and potential for future exploitation. Although no public exploit code is currently available, its high EPSS score suggests a higher-than-average likelihood of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2026.1CPE matchmatch criteria | cpe:2.3:a:solarwinds:web_help_desk:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.