SolarWinds Security Updates – 01 February 2026

SolarWinds has released security updates to address several vulnerabilities affecting multiple SolarWinds products.

The addressed vulnerabilities could allow the attacker to bypass security restrictions, gain unauthorized administrative access using the client user account, execute arbitrary code, and gain access to the affected system.

Sample of the addressed vulnerabilities:

1. SolarWinds Web Help Desk Authentication Bypass Vulnerability (CVE-2025- 40552):

  • CVSS: 9.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Bypass Security

2. SolarWinds Web Help Desk Deserialization of Untrusted Data Remote Code Execution Vulnerability (CVE-2025-40551):

  • CVSS: 9.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Gain Access

The affected products:

  • SolarWinds Web Help Desk 12.8.8 HF1 and all previous versions.
  • SolarWinds Observability Self-Hosted 2025.4 and prior versions.
Vulnerabilities
  • CVE-2025-26391
  • CVE-2025-40553
  • CVE-2025-40554
  • CVE-2025-40536
  • CVE-2025-40551
  • CVE-2025-40537
  • CVE-2025-40552
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

SolarWinds Security Updates

 

References