Known vulnerabilities in Web Help Desk 12.8.5 Hotfix 2
Vendor:
SolarWinds
Software:
Web Help Desk
Version:
12.8.5 Hotfix 2
Software CPE:
cpe:2.3:a:solarwinds:whd:*:*:*:*:*:*:*:*
Website:
https://www.solarwinds.com/
Total vulnerabilities:
9
Public exploits:
5
Known exploited (KEV):
3
Highest CVSSv4 Score:
9.3
Vulnerabilities by Severity
2026.2.1
2026.2
12.8.8 Hotfix 2
2026.1
12.8.8 Hotfix 1
12.8.8
12.8.7 Hotfix 1
12.8.7
12.8.6
12.8.5 Hotfix 3
12.8.5 Hotfix 2
12.8.5 Hotfix 1
12.8.3
12.8.1.824 Hotfix 1
12.8
12.4.1 Hotfix 1
12.4.1
12.8.5
12.8.4
12.8.3 Hotfix 3
12.8.3 Hotfix 2
12.8.3 Hotfix 1
12.4.2
12.5.1
12.5.2
12.7.9
12.7.10
12.7.11
12.7.12
12.7.13
12.8.0
12.8.1
12.8.1.824
12.8.2
12.7.8 Hotfix 1
12.7.8
12.7.7 Hotfix 1
12.7.7
12.7.6 Hotfix 1
12.7.6
12.7.5 Hotfix 1
12.7.5
12.7.4 Hotfix 4
12.7.4 Hotfix 3
12.7.4 Hotfix 2
12.7.4 Hotfix 1
12.7.4
12.7.3 Hotfix 1
12.7.3
12.7.2 Hotfix 1
12.7.2
12.7.1 Hotfix 1
12.7.1
12.7
12.6 Hotfix 2
12.6 Hotfix 1
12.6
12.5 Hotfix 1
12.5
12.4.1.984 Hotfix 1 1766
12.4
12.3
12.2
12.1
Vulnerabilities (9)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU139619 - Resource exhaustion CVE-2026-28299 |
CWE-400 | High | 2026.2 | 27.07.2026 |
SB20260727222 |
||
| #VU122156 - Deserialization of Untrusted Data CVE-2025-40551 |
CWE-502 | Critical | 2026.1 | 30.01.2026 |
SB2026013035 |
||
| #VU122155 - Improper Authentication CVE-2025-40552 |
CWE-287 | Critical | 2026.1 | 30.01.2026 |
SB2026013035 |
||
| #VU122154 - Deserialization of Untrusted Data CVE-2025-40553 |
CWE-502 | Critical | 12.8.8 Hotfix 2, 2026.1 | 30.01.2026 |
SB2026013035 |
||
| #VU122153 - Improper Authentication CVE-2025-40554 |
CWE-287 | Critical | 2026.1 | 30.01.2026 |
SB2026013035 |
||
| #VU122152 - Improper Access Control CVE-2025-40536 |
CWE-284 | High | 2026.1 | 30.01.2026 |
SB2026013035 |
||
| #VU122151 - Use of Hard-coded Credentials CVE-2025-40537 |
CWE-798 | Medium | 2026.1 | 30.01.2026 |
SB2026013035 |
||
| #VU116030 - Deserialization of Untrusted Data CVE-2025-26399 |
CWE-502 | Critical | 12.8.7 Hotfix 1 | 23.09.2025 |
SB2025092357 |
||
| #VU113572 - Improper Restriction of XML External Entity Reference ('XXE') CVE-2025-26400 |
CWE-611 | Medium | 12.8.7 | 01.08.2025 |
SB2025080107 |