Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

SolarWinds RCE bug makes Cisa list as exploitation spreads | Computer Weekly

By Computer Weekly by By Computer Weekly
February 4, 2026
Home Uncategorized
Share on FacebookShare on Twitter


A critical vulnerability in SolarWinds’ Web Help Desk service has been added to the US Cybersecurity and Infrastructure Security Agency’s (Cisa’s) Known Exploited Vulnerabilities (Kev) catalogue as exploitation spreads in the wild.

CVE-2025-40551 was among six common vulnerabilities and exposures (CVEs) disclosed by SolarWinds in an advisory at the end of January. It arises from Common Weakness Enumeration (CWE) 502 – deserialisation of untrusted data, and left unaddressed, enables an attacker to achieve remote code execution (RCE) on the target system.

The five other flaws listed in SolarWinds 28 January advisory are: CVE-2025-40552, an authentication bypass vulnerability; CVE-2025-40553, another RCE flaw arising from deserialisation; CVE-2025-40554 a second authentication bypass; CVE-2025-40536, which enables attackers to bypass access controls; and CVE-2025-40537, which may enable privilege elevation. All bear either high or critical Common Vulnerability Scoring System (CVSS) markers.

An update from SolarWinds taking Web Help Desk to version 2026.1 has since fixed all six issues.

In his analysis, researcher Jimi Sebree of Horizon3.ai, who discovered CVE-2025-40551 in early December, described it as “easily exploitable” and encouraged users to update as soon as possible, especially since it can be exploited without authentication.

“Attackers don’t always need ‘zero-day’ magic when they can just lean on reliable, low-complexity techniques like deserialisation. These flaws get buried in trusted, boring platforms like help desks, and that’s exactly why they’re so dangerous,” said Joe Brinkley, head of threat research at offensive security specialist Cobalt.

“Risks like this are often overlooked until Cisa drops a Kev notice. The real headache isn’t just the RCE; it’s the chaining. Once you’ve got unauthenticated admin access, you’re not just looking at one box, you are now looking at lateral movement and full compromise.

“We often see orgs underestimate just how fast the turnaround is from a proof of concept hitting GitHub to active exploitation. If you’re not hitting this with proactive validation and simulation now, you’re already behind the curve. Patch now,” added Brinkley.

Widely-used product

SolarWinds Web Help Desk is a helpdesk and IT service management platform that runs ticketing, asset tracking, service level agreement (SLA) management and workflow automation for IT support teams. It is well in use at organisations of many different sizes, and previous flaws discovered in the product have been swiftly weaponised by threat actors in the past, so warnings over this latest set of vulnerabilities should be heeded.

Its addition to the Cisa catalogue indicates a potential high-level of exposure within the US federal government, and obliges all bodies in scope to complete their updates in a much shorter-than-usual timeline, by Friday 6 February in this case.

Dale Hoak, chief information security officer at RegScale, a Washington DC-area governance, risk and compliance (GRC) specialist said the short remediation window reflected the speed with which operational risk escalates when vulnerabilities move from theoretical to exploited.

“Many organisations still rely on periodic assessments, which struggle to keep pace with threats that evolve in days, not months,” said Hoak. “The limitation is not awareness of vulnerabilities, but the speed at which teams can validate exposure and enforce remediation. Continuous controls monitoring helps close this gap by turning patching and configuration changes into measurable, auditable actions. That shift is critical for maintaining resilience under real-world attack pressure.”



Source link

By Computer Weekly

By Computer Weekly

Next Post
IDEMIA Public Security Launches New Smart Credential Minidriver with Full ARM64 Support for the Microsoft Windows 11 Ecosystem

IDEMIA Public Security Launches New Smart Credential Minidriver with Full ARM64 Support for the Microsoft Windows 11 Ecosystem

Recommended.

5 Ways Identity-based Attacks Are Breaching Retail

5 Ways Identity-based Attacks Are Breaching Retail

July 8, 2025
Selon un nouveau rapport de la GSMA, des politiques du spectre plus intelligentes pourraient répondre aux besoins d’investissement dans le secteur de la téléphonie mobile en Europe

Selon un nouveau rapport de la GSMA, des politiques du spectre plus intelligentes pourraient répondre aux besoins d’investissement dans le secteur de la téléphonie mobile en Europe

December 10, 2025

Trending.

Weibo Publishes 2025 Environmental, Social and Governance Report

Weibo Publishes 2025 Environmental, Social and Governance Report

April 28, 2026
It Takes 2 Minutes to Hack the EU’s New Age-Verification App

It Takes 2 Minutes to Hack the EU’s New Age-Verification App

April 18, 2026
CTIA Names Preston Wise Senior Vice President of External and State Affairs

CTIA Names Preston Wise Senior Vice President of External and State Affairs

May 6, 2026
The AI Correction Will Not Be Evenly Distributed | Computer Weekly

The AI Correction Will Not Be Evenly Distributed | Computer Weekly

May 5, 2026
Match Group Announces First Quarter Results

Match Group Announces First Quarter Results

May 5, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio