Critical Denial-of-Service Vulnerability in SolarWinds Web Help Desk

Critical Denial-of-Service Vulnerability in SolarWinds Web Help Desk

First seen 5 Jun 2026, 16:52 UTC Heise.Dewww.solarwinds.com 78% similarity 69.2

Article Content

Browse articles
ThreatCluster

SolarWinds Web Help Desk is vulnerable to a denial-of-service attack (CVE-2026-28299), which can crash the server due to insufficient memory. This vulnerability affects all versions of the software, including 2026.1 and 2026.2. Additionally, there are critical vulnerabilities (CVE-2025-12762, CVE-2025-12763, CVE-2025-12765) that allow for code execution and TLS certificate verification bypass. As of now, there are no reports of active exploitation, but users are advised to upgrade to version 2026.2 to mitigate risks. The developers have implemented fixes and improved security measures in the latest version. The vulnerabilities were publicly disclosed on June 2, 2026, and the developers have provided guidance for users on upgrading. The overall impact could disrupt IT support services across affected organizations.

Key Points: • CVE-2026-28299 allows denial-of-service attacks, potentially crashing servers. • Multiple critical vulnerabilities in Web Help Desk could lead to code execution. • Users are urged to upgrade to version 2026.2 to mitigate these risks.

ThreatCluster AI

Timeline

2025-11-13
CVE-2025-12762, CVE-2025-12763, CVE-2025-12765 published
Critical vulnerabilities were disclosed that could allow code execution and TLS bypass in pgAdmin4 and Web Help Desk.
Heise.De
2026-06-02
CVE-2026-28299 published
SolarWinds disclosed a denial-of-service vulnerability affecting Web Help Desk, allowing server crashes.
www.solarwinds.com
Recent
Users advised to upgrade to version 2026.2
SolarWinds recommends upgrading to the latest version to address vulnerabilities and improve security.
www.solarwinds.com

Community

Browse all →

Tracked Entities in This Story