Known CVE
SolarWinds Web Help Desk < 12.8.7 - AjaxProxy Deserialization RCE
SolarWinds Web Help Desk contains an unauthenticated AjaxProxy deserialization remote code execution vulnerability, letting attackers run commands on the host machine without authentication, exploit requires no special privileges.
CVE-2025-26399
Critical2025CVSS 9.8CWE-502
cve2025 · solarwinds · webhelpdesk · deserialization · rce · kev · vkev · passive
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website