SolarWinds released Web Help Desk 2026.2.1 to fix two vulnerabilities affecting the help desk platform: CVE-2026-28323, a critical authentication-bypass flaw, and CVE-2026-28299, a high-severity denial-of-service issue. The authentication-bypass bug affects deployments with SAML 2.0 enabled and could allow a remote unauthenticated attacker to craft or relay a malicious SAMLResponse and establish a session without valid credentials. The denial-of-service flaw can be triggered through unauthenticated interaction with a Web Help Desk endpoint, potentially causing resource exhaustion and service crashes.
Security guidance accompanying the release said no active exploitation had been observed, but warned that Web Help Desk is frequently internet-facing and that the no-credentials requirement makes the authentication bypass a likely target. Organizations were urged to patch immediately, disable SAML 2.0 if patching is delayed, enforce MFA through an identity provider or VPN/ZTNA, protect SAML endpoints with WAF or reverse-proxy controls, and reduce public internet exposure. SolarWinds also announced that Web Help Desk 12.8.8 and earlier will lose engineering support and reach final end of life later in 2026, increasing pressure on customers running legacy versions to upgrade.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Arctic Wolf Labs published a security bulletin detailing the two SolarWinds Web Help Desk vulnerabilities, noting no active exploitation had been observed at the time. The bulletin warned that WHD is often internet-facing and recommended immediate patching and compensating controls if patching is delayed.
SolarWinds released fixes for CVE-2026-28323, a critical authentication-bypass flaw, and CVE-2026-28299, a high-severity denial-of-service flaw in SolarWinds Web Help Desk. Both issues were addressed in Web Help Desk version 2026.2.1.
SolarWinds published an end-of-life announcement for numerous legacy SolarWinds Web Help Desk versions and told customers running affected releases to transition to the latest WHD version. The notice covers versions including WHD 12.8.8 and earlier.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.