# CVE-2025-40551

## Summary

- **CVE ID:** CVE-2025-40551
- **Severity:** CRITICAL
- **CVSS Score:** 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-502
- **Published:** Jan 28, 2026
- **Last Modified:** Feb 26, 2026

## Description

SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication.

## Affected Products

- SolarWinds — Web Help Desk (12.8.8 HF1 and below)

## References

- [CNA](https://www.solarwinds.com/trust-center/security-advisories/CVE-2025-40551)
- [CNA](https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_2026-1_release_notes.htm)
- [CISA-ADP](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-40551)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 83.62%
- **EPSS Percentile:** 99.7

## Known Exploited Vulnerabilities (KEV)

- **Date Added:** Feb 3, 2026
- **Due Date:** Feb 6, 2026

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-09._