SolarWinds Security Updates – 30 July 2025

SolarWinds has released security updates to address multiple vulnerabilities affecting SolarWinds SWOSH and SolarWinds Web Help Desk.

The addressed vulnerabilities could allow the attacker to obtain sensitive information or gain elevated privileges to the affected product.

The addressed vulnerabilities:

1. SolarWinds Observability Self-Hosted Deserialization of Untrusted Data Privilege Escalation Vulnerability (CVE-2025-26397):

  • CVSS: 7.8
  • Attack Vector: Local
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: Gain Privilege

2. SolarWinds Web Help Desk XML External Entity Injection (XXE) Vulnerability (CVE-2025-26400):

  • CVSS: 5.3
  • Attack Vector: Network
  • Attack Complexity: High
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: Obtain Information
Vulnerabilities
  • CVE-2025-26397
  • CVE-2025-26400
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

SolarWinds Security Updates

References