Skip to content
Critical Denial-of-Service Vulnerability in SolarWinds Web Help Desk

Critical Denial-of-Service Vulnerability in SolarWinds Web Help Desk

First seen 5 Jun 2026, 16:52 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 6, 2026 at 16:24 UTC
  • CVE-2026-28299 allows denial-of-service attacks, potentially crashing servers.
  • Multiple critical vulnerabilities in Web Help Desk could lead to code execution.
  • Users are urged to upgrade to version 2026.2 to mitigate these risks.

SolarWinds Web Help Desk is vulnerable to a denial-of-service attack (CVE-2026-28299), which can crash the server due to insufficient memory. This vulnerability affects all versions of the software, including 2026.1 and 2026.2. Additionally, there are critical vulnerabilities (CVE-2025-12762, CVE-2025-12763, CVE-2025-12765) that allow for code execution and TLS certificate verification bypass. As of now, there are no reports of active exploitation, but users are advised to upgrade to version 2026.2 to mitigate risks. The developers have implemented fixes and improved security measures in the latest version. The vulnerabilities were publicly disclosed on June 2, 2026, and the developers have provided guidance for users on upgrading. The overall impact could disrupt IT support services across affected organizations.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 96d ago How this analysis works

Timeline

2025-11-13
CVE-2025-12762, CVE-2025-12763, CVE-2025-12765 published
Critical vulnerabilities were disclosed that could allow code execution and TLS bypass in pgAdmin4 and Web Help Desk.
Heise.De
2026-06-02
CVE-2026-28299 published
SolarWinds disclosed a denial-of-service vulnerability affecting Web Help Desk, allowing server crashes.
www.solarwinds.com
Recent
Users advised to upgrade to version 2026.2
SolarWinds recommends upgrading to the latest version to address vulnerabilities and improve security.
www.solarwinds.com

More articles in this cluster (2)

Following this threat?

Track CVE-2025-12762 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed