Safeguard
Vulnerability Analysis

SolarWinds Web Help Desk's Deserialization Problem, Confirmed for Ransomware

Two separate deserialization RCEs and a security-control bypass in Web Help Desk, one confirmed for ransomware use, plus a denial-of-service bug in Serv-U.

Safeguard Research Team
4 min read

SolarWinds had four vulnerabilities confirmed exploited over the past year, three of them in Web Help Desk — including a confirmed ransomware-associated deserialization bug — and a fourth in the Serv-U file transfer product.

CVE-2025-26399, CVSS 9.8, is an unauthenticated AjaxProxy deserialization remote code execution vulnerability in Web Help Desk, carrying CISA's confirmed ransomware campaign flag. CVE-2025-40551, also CVSS 9.8, is a separate untrusted-data deserialization vulnerability in the same product leading to remote code execution. CVE-2025-40536, CVSS 8.1, is a security-control bypass, also in Web Help Desk. CVE-2026-28318, CVSS 7.5, is a Serv-U denial-of-service vulnerability triggered by specially crafted requests.

Why Web Help Desk's three findings tell one continuous story

Two independent deserialization vulnerabilities and a security-control bypass, all in the same IT help desk and asset management platform, is a pattern this series has now documented repeatedly across multiple vendors: once a product is identified as carrying exploitable deserialization weaknesses, subsequent scrutiny — whether from researchers, attackers, or the vendor's own post-incident review — tends to surface more of the same class nearby. CVE-2025-26399's confirmed ransomware association, specifically through an AjaxProxy deserialization path, makes clear this isn't a hypothetical risk for Web Help Desk deployments; it's a demonstrated one.

Help desk and IT asset management platforms hold a specific kind of value for an attacker distinct from more obviously sensitive systems: they typically have integration credentials into broader IT infrastructure — Active Directory, asset inventories, sometimes remote access tooling — because their entire function is coordinating IT support activity across an organization's technology estate. A compromised help desk platform is frequently a reconnaissance goldmine and a credential source simultaneously, which is exactly the kind of target ransomware operators have shown sustained interest in throughout this year's findings.

What to check this week

Patch Web Help Desk against all three CVEs, verifying each fix independently rather than assuming a single update cycle resolved every deserialization and security-control issue in the product — the recurring pattern across other vendors in this series suggests checking thoroughly rather than assuming completeness.

Treat any unpatched Web Help Desk instance as a priority incident-response item given CVE-2025-26399's confirmed ransomware association, auditing what integration credentials and access the platform holds into your broader IT environment.

Review Serv-U's exposure to the denial-of-service vector in CVE-2026-28318, given how directly a file transfer service's availability affects whatever business processes depend on it operating continuously.

Why deserialization keeps finding IT management tools specifically

Help desk and asset management platforms share an architectural trait with several other products covered throughout this series: they process structured data from many sources — support tickets, asset scans, integration feeds from other systems — as a core function, and deserialization vulnerabilities thrive precisely in that kind of data-ingestion-heavy code path. A product built to flexibly accept and process varied structured input from multiple integrated systems is, almost by construction, a more likely home for this bug class than a narrower, single-purpose application would be.

A closing note on internet-facing help desk portals

Web Help Desk instances are frequently made reachable from outside the corporate network specifically to let remote employees and, in some deployments, external customers submit tickets — an operational convenience that directly creates the unauthenticated exposure these CVEs depend on, and worth a specific architecture review independent of patch status.

A final consideration on integration credentials specifically

Because help desk platforms typically hold service-account credentials into Active Directory and other core systems purely to function, an incident-response plan for a Web Help Desk compromise should assume those integration credentials require rotation as a default step, not a conditional one dependent on further investigation confirming they were actually touched.

One more note before closing

Serv-U's denial-of-service finding is easy to deprioritize relative to the three RCE-adjacent Web Help Desk findings, but any file-transfer availability outage during a time-sensitive business process deserves its own separate risk conversation.

How Safeguard helps

Safeguard's continuous inventory tracks IT service management and help desk platforms with the same rigor applied to more obviously security-critical infrastructure, recognizing — as this SolarWinds cluster and its confirmed ransomware association demonstrate — that a platform's unglamorous, purely operational role doesn't correlate with reduced attacker interest in what access it actually holds.

Never miss an update

Weekly insights on software supply chain security, delivered to your inbox.

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.