Reddit
SolarWinds Web Help Desk Pre-Auth RCE Vulnerability Disclosed
First seen 25 Feb 2026, 21:11 UTC
•
•48.7
Export
Article Content
Browse articles
CVE-2024-28988 is a pre-auth deserialization remote code execution vulnerability in SolarWinds Web Help Desk. It was reported through the Zero Day Initiative and disclosed in October 2024, but remained unpatched until September 2025, affecting users of the software. The vulnerability allows unauthorized access to systems using the affected software.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Timeline
2024-10-01
CVE-2024-28988 disclosed
2025-09-01
CVE-2024-28988 published
2026-02-25
Articles published discussing the vulnerability
More articles in this cluster
Continue Reading
Russian SVR Exploits SolarWinds and Other Vulnerabilities Against U.S. Networks
Cl0p Ransomware Group Claims Data Theft from Nearly 50 Companies
Chinese State Actor Compromises Notepad++ Update Infrastructure
SUNBURST Backdoor Exploits SolarWinds Supply Chain Vulnerability
Congressional Hearing on Microsoft’s Security Culture Post-SolarWinds Breach
Critical MOVEit Vulnerabilities Expose Organizations to Data Breaches