SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could allow an unauthenticated attacker to gain access to certain restricted functionality.
Is CVE-2025-40536 exploited?
Listed in the CISA KEV catalog on 2026-02-12.
Federal remediation due 2026-02-15.
Past that date by 181 days.
EPSS puts exploitation in the next 30 days at 72%.
Public exploit code: packaged in a public tool.
Public detection rules exist.
Which products and versions are affected?
No affected package list recorded here yet.
Is there a patch?
No patch identifier recorded here yet.
What PlainSec published about CVE-2025-40536
PlainSec has not published a story about this CVE.