CVE-2025-26399
- CVSS
- —
- EPSS
- 0.895 (99.8th percentile)
- CISA KEV
- Added 2026-03-09, due 2026-03-12
- Exploitation
- No report
- Public exploits
- 1 repositories
- State
- Unknown
Coverage
Actively exploitedCritical 95Huntress
Active Exploitation of SolarWinds Web Help Desk (CVE-2025-26399)
Huntress has observed active exploitation of a deserialization and remote code execution against the SolarWinds Web Help Desk software (CVE-2025-26399).
What we observed
- poc publishedpoc-in-github
- poc publishedpoc-in-github
- poc publishedpoc-in-github
- kev addedcisa-kev