# CVE-2025-26399

## Summary

- **CVE ID:** CVE-2025-26399
- **Severity:** CRITICAL
- **CVSS Score:** 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-502
- **Published:** Sep 23, 2025
- **Last Modified:** Aug 4, 2026

## Description

SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. This vulnerability is a patch bypass of CVE-2024-28988, which in turn is a patch bypass of CVE-2024-28986.

## Affected Products

- SolarWinds — Web Help Desk (12.8.7 and below)

## References

- [CNA](https://www.solarwinds.com/trust-center/security-advisories/CVE-2025-26399)
- [CNA](https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_12-8-7-hotfix-1_release_notes.htm)
- [CISA-ADP](https://www.microsoft.com/en-us/security/blog/2026/02/06/active-exploitation-solarwinds-web-help-desk/)
- [CISA-ADP](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-26399)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 89.50%
- **EPSS Percentile:** 99.8

## Known Exploited Vulnerabilities (KEV)

- **Date Added:** Mar 9, 2026
- **Due Date:** Mar 12, 2026

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-09._