THREAT OPS › Threat News › SolarWinds Web Help Desk Exploitation - February 2026
SolarWinds Web Help Desk Exploitation - February 2026
<h2 id="summary">Summary</h2> <ul> <li>On February 6, 2026, Microsoft <a href="https://www.microsoft.com/en-us/security/blog/2026/02/06/active-exploitation-solarwinds-web-help-desk/">reported</a> the exploitation of <a href="https://www.solarwinds.com/web-help-desk">SolarWinds Web Help Desk</a> (WHD) servers </li> <li>The exploitation facilitated multi-stage intrusions leveraging remote monitorin
MITRE ATT&CK techniques
Indicators of compromise
- 793d79b0637135298c821a762a98312ad7f3c7d1sha1
- df9c27d82e74eb51e39376f1af30d2beb738c673sha1
- 7ad65c2cfca7a6c54c74dbe6206e968234209f94sha1
- CVE-2025-26399cve
- CVE-2025-40536cve
- CVE-2025-40551cve
- https://www.solarwinds.com/web-help-deskurl
- https://www.solarwinds.com/trust-center/security-advisories/cve-2025-26399url
- https://www.solarwinds.com/trust-center/security-advisories/cve-2025-40536url
- https://www.solarwinds.com/trust-center/security-advisories/cve-2025-40551url
- https://support.solarwinds.com/web-help-deskurl
- https://docs.velociraptor.app/url
- https://catbox.moe/url
- https://files.catbox.moe/tmp9fc.msiurl
- https://www.qemu.org/url
- static-www.elastic.codomain
- vdfccjpnedujhrzscjtq.supabase.codomain