SolarWinds security advisory (AV26-766)
Serial number: AV26-766 Date: July 30, 2026 As of July 30, 2026, SolarWinds is affected by a vulnerability in the following product: Web Help Desk (WHD) Prior to 2026.2.1 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. WHD 2026.2.1 release notes SolarWinds Web Help Desk SAML Authentication Bypass Vulnerability (CVE-2026-28323) SolarWinds Security Vulnerabilities
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/solarwinds-security-advisory-av26-766
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-283230.64% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 47% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-28323 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownNCSC-2026-0274 [1.00] [M/H] Kwetsbaarheid verholpen in SolarWinds Web Help Deskncsc-nl
- high[NEU] [hoch] SolarWinds Web Help Desk: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungencert-bund
- criticalCVE-2026-28323: SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability…nvd
More from Canadian Centre for Cyber Security
- unknownGoogle security advisory (AV26-768)2026-07-31
- unknownRails security advisory (AV26-767)2026-07-31
- unknownGladinet security advisory (AV26-765)2026-07-30
- unknownPHP Group security advisory (AV26-764)2026-07-30
- unknownVMware security advisory (AV26-763)2026-07-30