SolarWinds warned that multiple vulnerabilities in Web Help Desk are being actively exploited, with reporting highlighting a critical flaw that can lead to remote code execution on exposed help-desk servers. Public references tie the activity to CVE-2025-40554, while additional SolarWinds advisories and third-party research point to related issues including CVE-2025-40552, CVE-2025-40553, and CVE-2025-40536, indicating a broader security problem affecting the product.
Security researchers and defenders published proof-of-concept material and detection guidance shortly after disclosure, including a watchTowr repository focused on Web Help Desk exploitation and a GitHub Gist describing uncommon process activity associated with compromise. The combination of vendor advisories, media reporting, and public exploit research indicates that attackers moved quickly to weaponize the flaws, increasing risk for organizations that have not patched, isolated, or monitored SolarWinds Web Help Desk deployments.

See which actors are running it and whether you're in range.
6 events from the most recent confirmed update back to the earliest known activity.
SolarWinds published a Trust Center security advisory for CVE-2025-40554. The reference explicitly anchors this advisory to January 1, 2026.
watchTowr Labs published a GitHub repository focused on SolarWinds Web Help Desk vulnerabilities CVE-2025-40552 and CVE-2025-40553. This represents public release of additional technical material related to the flaws.
A GitHub Gist titled "SolarWinds Web Help Desk Exploitation - Uncommon Process Activity" was published, indicating technical detection details related to the exploitation activity were made available.
Microsoft reported that exploitation of Internet-exposed SolarWinds Web Help Desk servers, reportedly active since December 2025, involved RMM tooling, Velociraptor and Cloudflared abuse, TPMProfiler scheduled-task QEMU tunneling, defense evasion, and NTDS.dit extraction and DCSync. The initial-access CVE was not confirmed.
News coverage reported that a critical vulnerability in SolarWinds Web Help Desk was being actively exploited. Multiple outlets covered the same development in early February 2026.
SolarWinds published a Trust Center security advisory for CVE-2025-40536. This is the earliest explicitly dated event present in the references.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
8 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourceelastic.co
Open sourcegist.github.com
Open sourcemicrosoft.com
Open sourcecybersecuritydive.com
Open sourceinfosecurity-magazine.com
Open sourcesolarwinds.com
Open sourcesolarwinds.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.