CVE-2025-40554: exploitation status and patch state
CVE-2025-40554 · CVSS 9.8 CRITICAL · EPSS 57%
SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that, if exploited, could allow an attacker to invoke specific actions within Web Help Desk.
Is CVE-2025-40554 exploited?
Not in the CISA KEV catalog.
EPSS puts exploitation in the next 30 days at 57%.
Public exploit code: none found in monitored sources.
Public detection rules exist.
Which products and versions are affected?
No affected package list recorded here yet.
Is there a patch?
No patch identifier recorded here yet.
What PlainSec published about CVE-2025-40554
PlainSec has not published a story about this CVE.