Attackers are quickly exploiting a remote code execution vulnerability in SolarWinds Web Help Desk, using compromised systems to deploy legitimate but misused administrative tools.
Huntress observed that 84 endpoints in 78 partner organizations are using SolarWinds Web Help Desk, highlighting significant vulnerability.
Huntress observedpost-exploitation activity originating from a compromised WHD service. The attack chain began with wrapper.exe, the WHD service wrapper, spawning java.exe the underlying Tomcat-based application. From there, the Java process executed cmd.exe to silently install a remote MSI payload:
This payload installed a Zoho ManageEngine RMM (Zoho Assist) agent using the Catbox file-hosting service. Although Zoho Assist is a legitimate tool, it is often misused post-exploitation for persistent access. Here, the agent was linked to an attacker-controlled Zoho account with a Proton Mail address, allowing for instant control.
Help Desk Attack Timeline
This activity aligns closely with Microsoft’s February 6 advisory confirming in-the-wild exploitation of SolarWinds WHD vulnerabilities for RCE and follow-on tooling deployment.
Organizations using SolarWinds Web Help Desk need to update to version 2026.1 or later, which fixes CVE-2025-26399, CVE-2025-40536, and CVE-2025-40551.