Skip to content
Attackers can disable SolarWinds Web Help Desk

Attackers can disable SolarWinds Web Help Desk

Heise.De June 3, 2026

SolarWinds' IT support software Web Help Desk is vulnerable. Attackers can crash instances or even execute malicious code. One security vulnerability is in the software itself, while other vulnerabilities affect components that Web Help Desk uses. The developers have closed the vulnerabilities in a current version. So far, there are no indications of attacks.

If attackers successfully exploit the vulnerability in Web Help Desk (CVE-2026-28299 " high "), the Web Help Desk server will crash. Consequently, IT support in companies will no longer be available. A " critical " vulnerability (CVE-2025-12762) affects pgAdmin4. Here, attackers can execute malicious code. How this could happen specifically is not yet known.

Malicious code can also get onto systems via the further vulnerabilities (e.g., CVE-2025-12763 " high "). Or attackers bypass TLS certificate verification (CVE-2025-12765 " high ").

The developers assure that SolarWinds Web Help Desk 2026.2 has been repaired. The warning message reads as if all versions are vulnerable. SolarWinds points out that users of earlier versions should first upgrade to 2026.1 and only then to the current version. Apparently, otherwise, operating errors may occur.

In the current version, the developers have also improved secure operation through adjustments: For example, only TLS 1.2 and TLS 1.3 are supported from now on. In addition, only modern, recommended cipher suites are enabled by default. Furthermore, the developers have resolved several bugs and the current version now supports Windows Server 2025.

This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.

Extracted Entities