CISA warns critical SolarWinds RCE bug is exploited in attacks

Share:

CISA warned on Thursday that attackers are exploiting a recently patched critical vulnerability in SolarWinds’ Web Help Desk solution for customer support.

Web Help Desk (WHD) is IT help desk software widely used by large corporations, government agencies, and healthcare and education organizations worldwide to centralize, automate, and streamline help desk management tasks.

Tracked as CVE-2024-28986, this Java deserialization security flaw allows threat actors to gain remote code execution on vulnerable servers and run commands on the host machine following successful exploitation.

SolarWinds issued a hotfix for the vulnerability on Wednesday, a day before CISA’s warning. However, the company did not disclose any information about in-the-wild exploitation, although it recommended all administrators apply the fix to vulnerable devices.

“While it was reported as an unauthenticated vulnerability, SolarWinds has been unable to reproduce it without authentication after thorough testing. However, out of an abundance of caution, we recommend all Web Help Desk customers apply the patch, which is now available,” SolarWinds said.

“WHD 12.8.3 Hotfix 1 should not be applied if SAML Single Sign-On (SSO) is utilized. A new patch will be available shortly to address this problem.”

SolarWinds also published a support article with detailed instructions on applying and removing the hotfix, warning that admins must upgrade vulnerable servers to Web Help Desk 12.8.3.1813 before installing the hotfix.

The company recommends creating backups of the original files before replacing them during the installation process to avoid potential issues if the hotfix deployment fails or the hotfix isn’t applied correctly.

CISA added CVE-2024-28986 to its ts KEV catalog on Thursday, mandating federal agencies to patch their WHD servers within three weeks, until September 5, as required by the Binding Operational Directive (BOD) 22-01.

Earlier this year, SolarWinds also patched over a dozen critical remote code execution (RCE) flaws in its Access Rights Manager (ARM) software, eight in July and five in February.

In June, cybersecurity firm GreyNoise warned that threat actors were already exploiting a SolarWinds Serv-U path-traversal vulnerability, just two weeks after SolarWinds released a hotfix and days after proof-of-concept (PoC) exploits were published online.

SolarWinds says that the company’s IT management products are being used by more than 300,000 customers worldwide.

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
6:28 am, Jul 9, 2025
weather icon 13°C
L: 11° | H: 15°
scattered clouds
Humidity: 82 %
Pressure: 1020 mb
Wind: 3 mph WNW
Wind Gust: 5 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 49%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:54 am
Sunset: 9:16 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
11° | 15°°C 0.03 mm 3% 7 mph 82 % 1022 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
18° | 29°°C 0 mm 0% 8 mph 71 % 1023 mb 0 mm/h
Fri Jul 11 10:00 pm
weather icon
19° | 29°°C 0 mm 0% 8 mph 62 % 1022 mb 0 mm/h
Sat Jul 12 10:00 pm
weather icon
19° | 30°°C 0 mm 0% 10 mph 63 % 1019 mb 0 mm/h
Sun Jul 13 10:00 pm
weather icon
18° | 31°°C 0 mm 0% 9 mph 70 % 1018 mb 0 mm/h
Today 7:00 am
weather icon
13° | 14°°C 0 mm 0% 3 mph 82 % 1021 mb 0 mm/h
Today 10:00 am
weather icon
15° | 21°°C 0 mm 0% 4 mph 72 % 1021 mb 0 mm/h
Today 1:00 pm
weather icon
20° | 24°°C 0 mm 0% 6 mph 60 % 1021 mb 0 mm/h
Today 4:00 pm
weather icon
26° | 26°°C 0.03 mm 3% 7 mph 42 % 1021 mb 0 mm/h
Today 7:00 pm
weather icon
25° | 25°°C 0 mm 0% 3 mph 43 % 1021 mb 0 mm/h
Today 10:00 pm
weather icon
22° | 22°°C 0 mm 0% 3 mph 57 % 1022 mb 0 mm/h
Tomorrow 1:00 am
weather icon
20° | 20°°C 0 mm 0% 3 mph 62 % 1022 mb 0 mm/h
Tomorrow 4:00 am
weather icon
18° | 18°°C 0 mm 0% 4 mph 71 % 1022 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€92,612.23
0.46%
Ethereum(ETH)
€2,225.18
2.40%
Tether(USDT)
€0.85
0.02%
XRP(XRP)
€1.98
2.23%
Solana(SOL)
€129.30
1.78%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.145930
1.91%
Shiba Inu(SHIB)
€0.000010
1.39%
Pepe(PEPE)
€0.000009
2.57%
Scroll to Top