>

SolarWinds Web Help Desk RCE: The Name That Hurts Again

On August 21-22, 2024, SolarWinds shipped 12.8.3 HF1 for Web Help Desk and disclosed CVE-2024-28986 — an unauthenticated Java deserialization flaw rated CVSS 9.8 that delivers pre-auth remote code execution on internet-facing instances. Within days PoC code circulated in exploitation attempts, and on August 26 CISA added it to the Known Exploited Vulnerabilities catalog, making patching mandatory across federal networks. This account covers the bug mechanics, the four-day disclosure-to-KEV sprint, and the uncomfortable optics of a SolarWinds product back in emergency-cycle headlines.

Continue ReadingSolarWinds Web Help Desk RCE: The Name That Hurts Again
>