CISA orders federal agencies to patch exploited SolarWinds bug by Friday
好的,我现在需要帮用户总结这篇文章的内容。用户的要求是用中文,控制在100个字以内,而且不需要特定的开头,直接写描述即可。首先,我得仔细阅读文章内容,抓住关键点。 文章主要讲的是SolarWinds公司的Web Help Desk工具存在一个严重漏洞CVE-2025-40551,评分高达9.8。这个漏洞被黑客利用,美国网络安全机构CISA要求联邦机构在周五前修复。漏洞是由Horizon3.ai的研究员发现的,并且提到了之前的一个漏洞CVE-2024-28986。SolarWinds已经发布了修复补丁。 接下来,我需要把这些信息浓缩到100字以内。重点包括:SolarWinds工具的漏洞、评分、影响、发现者、CISA的要求、修复情况以及与之前漏洞的关系。 可能会这样组织:SolarWinds的Web Help Desk有严重漏洞(CVE-2025-40551),评分9.8,被黑客利用。CISA要求联邦机构周五前修复。该漏洞由Horizon3.ai发现,与之前的CVE-2024-28986有关。SolarWinds已发布补丁修复。 检查一下字数是否合适,并确保信息准确无误。 </think> SolarWinds的Web Help Desk工具存在严重漏洞CVE-2025-40551(评分9.8),已被黑客利用。CISA要求联邦机构于周五前修复该漏洞,该漏洞由Horizon3.ai的研究员发现,并与此前的CVE-2024-28986相关。SolarWinds已发布补丁修复此问题。 2026-2-3 21:1:15 Author: therecord.media(查看原文) 阅读量:0 收藏

A vulnerability affecting a popular IT help desk tool from software company SolarWinds is being exploited by hackers, according to the U.S. cyber defense agency. 

Federal civilian agencies will have until Friday to patch CVE-2025-40551, a critical vulnerability reported by SolarWinds last week. The company said security researchers at Horizon3.ai discovered the vulnerability and reported it to them. 

CVE-2025-40551 carries a critical severity score of 9.8 out of 10 and impacts SolarWinds Web Help Desk (WHD) — an IT service management platform used by many large organizations to handle  ticketing, asset tracking and other tasks. The tool helps companies centralize IT support operations.

Horizon3.ai researcher Jimi Sebree published a blog about the bug that traced the issue back to another vulnerability discovered in 2024. That bug, CVE-2024-28986, was also added to these Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities list at the time. 

According to Sebree, CVE-2025-40551 is the latest in a series of bugs that are centered around bypasses of fixes to CVE-2024-28986. Sebree discovered and reported CVE-2025-40551 to SolarWinds on December 5. 

Solarwinds has published an update in Web Help Desk version 2026.1 that fixes the issues. The company fixed CVE-2025-40551 and several other security bugs that were recently discovered by researchers. 

CISA added CVE-2025-40551 to the Known Exploited Vulnerabilities catalog alongside three other vulnerabilities that federal civilian agencies will need to patch before the end of the month.

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.


文章来源: https://therecord.media/cisa-orders-agencies-patch-solarwinds-vuln
如有侵权请联系:admin#unsafe.sh