Vulnerability Management, Patch/Configuration Management, Threat Intelligence

CISA: Attacks leveraging critical SolarWinds RCE underway

Share
A SolarWinds sign sits on top of an office building.

BleepingComputer reports that organizations have been warned by the Cybersecurity and Infrastructure Security Agency regarding ongoing intrusions targeting SolarWinds Web Help Desk instances vulnerable to the critical Java deserialization flaw, tracked as CVE-2024-28986, which could be leveraged to facilitate remote code execution.

In-the-wild exploitation of the vulnerability should prompt federal agencies to apply remediations by Sep. 5, according to the CISA advisory. Such a warning comes a day after a hotfix was released by SolarWinds, which has not yet reported active targeting of the security issue at the time. "While it was reported as an unauthenticated vulnerability, SolarWinds has been unable to reproduce it without authentication after thorough testing. However, out of an abundance of caution, we recommend all Web Help Desk customers apply the patch, which is now available," noted SolarWinds, which committed to providing an updated patch to address the bug soon. SolarWinds has been reported to have fixed 13 RCE flaws impacting its Access Rights Manager software so far this year.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.