SolarWinds patches critical Web Help Desk authentication-bypass flaw CVE-2026-28323 and related denial-of-service bug CVE-2026-28299

SolarWinds fixed two serious flaws in its Web Help Desk software that could let outsiders get in without valid credentials or crash the service. The issues are CVE-2026-28323, a critical authentication bypass affecting Web Help Desk when Security Assertion Markup Language (SAML) 2.0 is enabled, and CVE-2026-28299, a high-severity denial-of-service bug reachable without authentication. SolarWinds says both are fixed in Web Help Desk 2026.2.1.
Why it matters: Organizations running internet-facing SolarWinds Web Help Desk should treat this as urgent because one flaw can allow remote access without a password. Update to Web Help Desk 2026.2.1 or later now, and if you cannot patch immediately, disable SAML 2.0 and restrict access behind virtual private network (VPN) or zero trust network access (ZTNA) with multi-factor authentication.

Sources

SolarWinds Web Help Desk Vulnerabilities: CVE-2026-28323 and CVE-2026-28299
Arctic Wolf Labs 2026.08.06 100% relevant
This article establishes a trackable event: SolarWinds released fixes for CVE-2026-28323 and CVE-2026-28299 in Web Help Desk and published actionable mitigation guidance for exposed deployments.
← Back to all stories