SolarWinds has released hot fixes to address a critical security flaw impacting its Web Help Desk software that, if successfully exploited, could allow attackers to execute arbitrary commands on susceptible systems. It affects SolarWinds Web Help Desk 12.8.7 and all previous versions. "SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine," SolarWinds said in an advisory released on September 17, 2025. "This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Web Help Desk. "Fast forward to 2024: an unauthenticated remote deserialization vulnerability (CVE-2024-28986) was patched... then patched again (CVE-2024-28988).