LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-26399: SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 9, 2026
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Mar 12, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-26399 to its Known Exploited Vulnerabilities catalog on Mar 9, 2026, with a federal patch deadline of Mar 12, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

SolarWinds Web Help Desk contain a deserialization of untrusted data vulnerability in AjaxProxy that could allow an attacker to run commands on the host machine.

This vulnerability, tracked as CVE-2025-26399, affects SolarWinds Web Help Desk. It stems from a deserialization of untrusted data weakness that could allow an attacker to execute commands on the host system. The issue is located in the AjaxProxy component. Organizations that rely on this product for IT support ticket handling should treat it as a remote code execution risk until confirmed otherwise through official channels.

How it works

The weakness is categorized as CWE-502, deserialization of untrusted data. In this class of flaw, an application accepts serialized input without sufficient validation and reconstructs objects from that input.

An attacker can supply crafted serialized data to the AjaxProxy component. When the application deserializes the data, it may result in unintended code execution on the underlying host. Specific mechanics of exploitation, affected code paths, and required preconditions must be confirmed against the vendor advisory.

Am I affected? How to find it in your systems

SolarWinds Web Help Desk is typically deployed as an on-premises or self-hosted application used by IT teams to manage service requests. Inventory all instances by checking server deployments, container images, and configuration management databases for the product name.

How to remediate

Apply the vendor-supplied update referenced in the official advisory as the primary remediation step. Follow the installation and verification instructions provided by the vendor.

If you can't patch immediately

Until a patch can be applied, implement network segmentation to isolate the Web Help Desk server from broader internal networks and the internet. Consider virtual patching through a web application firewall that can inspect and block malformed serialized payloads targeting the affected component.

If your data may have been exposed

Deserialization vulnerabilities that permit remote code execution have been used to establish persistent access in past incidents. Run a free exposure scan of your organization's email domains against known breach data to identify any related account compromises.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedSolarWinds · Web Help Desk
WeaknessCWE-502
Added to CISA KEVMar 9, 2026
Federal patch deadlineMar 12, 2026
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities