BleepingComputer reports that intrusions leveraging the critical SolarWinds Web Help Desk flaws, tracked as CVE-2025-40551 and CVE-2026-26399, to deliver legitimate tools for illicit activity have been launched as part of a campaign believed to have commenced in mid-January.
The vulnerability, an improper neutralization of special elements used in an SQL command, enables remote attackers to run malicious code without prior authentication.
The vulnerability, CVE-2026-1731, is a pre-authentication remote code execution flaw that can be exploited through low-complexity attacks requiring no user interaction.