Skip to content
SolarWinds Web Help Desk Pre-Auth RCE Vulnerability Disclosed

SolarWinds Web Help Desk Pre-Auth RCE Vulnerability Disclosed

First seen 25 Feb 2026, 21:11 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 16:10 UTC

CVE-2024-28988 is a pre-auth deserialization remote code execution vulnerability in SolarWinds Web Help Desk. It was reported through the Zero Day Initiative and disclosed in October 2024, but remained unpatched until September 2025, affecting users of the software. The vulnerability allows unauthorized access to systems using the affected software.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 212d ago How this analysis works

Timeline

2024-10-01
CVE-2024-28988 disclosed
2025-09-01
CVE-2024-28988 published
2026-02-25
Articles published discussing the vulnerability

More articles in this cluster (2)

Following this threat?

Track SolarWinds and CVE-2024-28988 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed