惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Last Week in AI
Last Week in AI
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
博客园_首页
雷峰网
雷峰网
IT之家
IT之家
I
InfoQ
酷 壳 – CoolShell
酷 壳 – CoolShell
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
B
Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园 - 【当耐特】
大猫的无限游戏
大猫的无限游戏
博客园 - 聂微东
Hugging Face - Blog
Hugging Face - Blog
A
About on SuperTechFans
月光博客
月光博客
P
Proofpoint News Feed
博客园 - 三生石上(FineUI控件)
J
Java Code Geeks
G
Google Developers Blog
小众软件
小众软件
宝玉的分享
宝玉的分享
Jina AI
Jina AI
V
Visual Studio Blog

The Register - Security: Patches

Homeland security cybercops say patch TrueConf (Russia Microsoft Defender for Endpoint leaves some Linux boxes defenseless after update Year-long Russian attacks infect users as soon as they look at an email Cisco SD-WAN make-me-root bug under attack Ivanti tells Sentry customers to patch now as critical bugs hit 10.0 and 9.9 AI is making Patch Tuesday (kinda) fun again Anthropic to release Mythos-class models to the public Clear your calendar, Drupal user: You have a critically urgent patch to install Welcome to the vulnpocalypse, as vendors use AI to find bugs and patches multiply like rabbits Doozy of a Patch Tuesday includes 30 critical Microsoft CVEs Critical cPanel, WHM flaw probs exploited as 0-day, pros say Microsoft patch fell short. New Windows flaw exploited More Cisco SD-WAN bugs battered in attacks Critical Fortinet sandbox bugs allow auth bypass and RCE Ancient Excel bug comes out of retirement for active attacks Microsoft's massive Patch Tuesday: It's raining bugs Ransomware scum, other crims exploit 4 old Microsoft bugs Attackers exploited the FortiClient EMS bug as a 0-day Citrix NetScaler bug may be multiple flaws in one Ransomware crims abused Cisco 0-day weeks before disclosure Google rushes Chrome update to fix zero-days under attack CISA warns max-severity n8n bug is being exploited in the wild Cisco warns of two more SD-WAN bugs under active attack LexisNexis Legal & Professional confirms data breach Five Eyes warn: Patch your Cisco SD-WAN or risk root takeover Patch these 4 critical, make-me-root SolarWinds bugs ASAP Attacker gets into France's DB listing all bank accounts CISA gives feds 3 days to patch actively exploited Dell bug CISA gives feds 3 days to patch actively exploited Dell bug Google fixes exploited Chrome CSS zero-day
SolarWinds patches critical RCE - for the third time
Jessica Lyons · 2025-09-24 · via The Register - Security: Patches

Patches

Third time's the charm? SolarWinds (again) patches critical Web Help Desk RCE

Or maybe 3 strikes, you're out?

SolarWinds on Tuesday released a hotfix - again - for a critical, 9.8-severity flaw in its Web Help Desk IT ticketing software that could allow a remote, unauthenticated attacker to run commands on a host machine. 

This is the third time the vendor has tried to fix this flaw, an unauthenticated, AJAXproxy deserialization remote code execution (RCE) bug in its Web Help Desk ticketing and asset management software.

"This vulnerability is a patch bypass of CVE-2024-28988, which in turn is a patch bypass of CVE-2024-28986," SolarWinds noted in its Tuesday release. Criminals exploited both of those earlier vulnerabilities.

It all started in mid-August 2024, when the software maker released a hotfix for CVE-2024-28986, a critical (9.8 CVSS) deserialization RCE vulnerability in Web Help Desk. CISA later added this flaw to its Known Exploited Vulnerabilities catalog.

Then in October 2024, SolarWinds disclosed and tried to patch CVE-2024-28988, another 9.8-rated Web Help Desk Java deserialization RCE bug, which Trend Micro's Zero Day Initiative (ZDI) spotted while researching CVE-2024-28986. "The ZDI team was able to discover an unauthenticated attack during their research," SolarWinds said at the time.

And that brings us to CVE-2025-26399, the new vuln. "Anonymous," working with ZDI, is also credited with finding and reporting this flaw to SolarWinds. A SolarWinds spokesperson told The Register that the company is not aware of any exploitation as of yet.

However, as threat intel firm watchTowr warned on social media: "Given SolarWinds' past, in-the-wild exploitation is highly likely. Patch now."

SolarWinds is widely known for the backdoor Russian actors maliciously added to its Orion suite in a supply-chain attack back in 2020.

"SolarWinds is a name that needs no introduction in IT and cybersecurity circles," Ryan Dewhurst, head of proactive threat intelligence at watchTowr, told The Register. "The infamous 2020 supply chain attack, attributed to Russia's Foreign Intelligence Service (SVR), allowed months-long access into multiple Western government agencies and left a lasting mark on the industry."

In 2024, the software vendor twice tried to patch the newer unauthenticated remote deserialization vulnerability, he noted.

"And now, here we are with yet another patch (CVE-2025-26399) addressing the very same flaw," Dewhurst said. "Third time's the charm?" ®