A critical deserialization vulnerability (CVE-2025-6544) in H2O-3 versions <= 3.46.0.8 enables remote attackers to read arbitrary files and execute code. The flaw is due to improper handling of JDBC connection parameters, which can be exploited by bypassing input validation using double URL encoding. All users of affected versions are at risk and should update to version 3.46.0.9 or later.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
National and regional defenders including the Canadian Centre for Cyber Security and CERT-EU published advisories warning about the critical SolarWinds Web Help Desk vulnerability. These notices amplified remediation guidance following SolarWinds' hotfix release.
The Zero Day Initiative published advisory ZDI-25-906 covering the AjaxProxy deserialization of untrusted data vulnerability in SolarWinds Web Help Desk. The advisory publicly documented the technical class of the bug and its remote code execution impact.
On or before September 23, 2025, SolarWinds released Web Help Desk 12.8.7 Hotfix 1 to address CVE-2025-26399, a critical 9.8-severity remote code execution vulnerability affecting version 12.8.7 and earlier. The company said there was no evidence of active exploitation in the wild and urged customers to upgrade.
An anonymous researcher working with Trend Micro's Zero Day Initiative reported CVE-2025-26399, an unauthenticated AjaxProxy deserialization flaw in SolarWinds Web Help Desk. SolarWinds said the issue bypasses the prior fix for CVE-2024-28988, which itself bypassed CVE-2024-28986.
Shortly after disclosure, CISA added CVE-2024-28986 to its Known Exploited Vulnerabilities catalog, indicating confirmed exploitation of the earlier Web Help Desk flaw. Public details of that exploitation were not disclosed in the referenced coverage.
SolarWinds originally patched the Web Help Desk remote code execution flaw CVE-2024-28986 in August 2024. Later reporting says this bug was subsequently exploited and became the basis for later patch-bypass issues.
13 references tracked. Mallory keeps watching after this page renders.
thecyberexpress.com
Open sourcecert.europa.eu
Open sourcesecurityaffairs.com
Open sourcescworld.com
Open sourcezerodayinitiative.com
Open sourcebleepingcomputer.com
Open sourcecisecurity.org
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.