<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — SolarWinds</title><description>Actively exploited vulnerabilities affecting SolarWinds products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/solarwinds.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-28318 — SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability</title><link>https://wildfortech.com/security#CVE-2026-28318</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2026-28318</guid><description>This vulnerability in SolarWinds Serv-U allows any unauthenticated attacker to crash the file transfer service by sending a specially crafted POST request using a deflate content-encoding header. Because no authentication is required, the attack surface is wide — anyone who can reach the Serv-U service over the network can trigger a denial of service, taking the service offline and disrupting file transfer operations until it is restarted or patched.</description><pubDate>Fri, 05 Jun 2026 00:00:00 GMT</pubDate><category>SolarWinds</category><category>Serv-U</category></item><item><title>CVE-2025-26399 — SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-26399</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-26399</guid><description>SolarWinds Web Help Desk contains a deserialization flaw in its AjaxProxy component that allows an attacker to execute arbitrary commands directly on the host machine. This is a critical remote code execution class vulnerability, and it has already been linked to real ransomware attacks in the wild. Any organization running Web Help Desk is at risk of full system compromise, making this an urgent priority for IT and security teams.</description><pubDate>Mon, 09 Mar 2026 00:00:00 GMT</pubDate><category>SolarWinds</category><category>Web Help Desk</category></item><item><title>CVE-2025-40536 — SolarWinds Web Help Desk Security Control Bypass Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-40536</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-40536</guid><description>SolarWinds Web Help Desk has a flaw that lets unauthenticated attackers bypass security controls and reach functionality that should be restricted to authorized users. Because no login is required to exploit this, the attack surface is broad — anyone who can reach the application over the network is a potential threat actor. Help desk platforms typically handle sensitive tickets, credentials, and user data, making unauthorized access particularly damaging.</description><pubDate>Thu, 12 Feb 2026 00:00:00 GMT</pubDate><category>SolarWinds</category><category>Web Help Desk</category></item><item><title>CVE-2025-40551 — SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-40551</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-40551</guid><description>SolarWinds Web Help Desk contains a deserialization flaw that allows attackers to execute arbitrary commands on the underlying host machine without any credentials. Deserialization vulnerabilities are particularly dangerous because they can be triggered remotely and require no prior access or authentication, giving attackers a direct path to full system compromise. Any organization running this product is potentially exposed to complete server takeover.</description><pubDate>Tue, 03 Feb 2026 00:00:00 GMT</pubDate><category>SolarWinds</category><category>Web Help Desk</category></item></channel></rss>