Skip to content

Known CVE

SolarWinds Web Help Desk < 12.8.7 - AjaxProxy Deserialization RCE

SolarWinds Web Help Desk contains an unauthenticated AjaxProxy deserialization remote code execution vulnerability, letting attackers run commands on the host machine without authentication, exploit requires no special privileges.

CVE-2025-26399

Critical2025CVSS 9.8CWE-502

cve2025 · solarwinds · webhelpdesk · deserialization · rce · kev · vkev · passive

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website