CVE-2025-40554
critical · 9.8A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that, if exploited, could allow an attacker to invoke specific actions within Web Help Desk.
9.8
CVSS
59.2%
EPSS (exploit prob.)
99th
EPSS percentile
2026-01-28
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-1390
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| solarwinds | web_help_desk | < 2026.1 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2025-40554