CVE-2025-40551
Exploited in the Wild
✓ Confirmed 0-Day
Triaged: March 5, 2026
5 articles
EPSS Score
Source: FIRST.org · 2026-05-24
86.97%
probability
This CVE has a 86.97% probability
of being exploited in the next 30 days.
0%
Top 99.4th percentile of all CVEs
100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE.
View on VulnerabilityLookup ↗
Attack Intelligence
⚡ Weekly Recap: Proxy Botnet, Office Zero-Day, MongoDB Ransoms, AI Hijacks & New Threats
TheHackerNews
Feb 02, 2026
Researchers Observe In-the-Wild Exploitation of BeyondTrust CVSS 9.9 Vulnerability
TheHackerNews
Feb 13, 2026
SolarWinds Web Help Desk Exploited for RCE in Multi-Stage Attacks on Exposed Servers
TheHackerNews
Feb 09, 2026
CISA Adds Actively Exploited SolarWinds Web Help Desk RCE to KEV Catalog
TheHackerNews
Feb 04, 2026
SolarWinds Fixes Four Critical Web Help Desk Flaws With Unauthenticated RCE and Auth Bypass
TheHackerNews
Jan 29, 2026
Signal Intelligence
Confidence
95%
EPSS
86.97%
Mentions
5
Last Seen
Feb 13, 2026
CNA Information
Analyst Note
CVE-2025-40551 shows clear zero-day indicators: active exploitation documented in the wild (Microsoft observed multi-stage attacks), CISA added it to KEV catalog as actively exploited, and the CVE was published 2026-01-28 with exploitation occurring before or concurrent with patch availability. The critical CVSS 9.8 unauthenticated RCE combined with documented real-world attacks confirms zero-day status.
Threat Actors 4
APT 28
apt_group
Information theft and espionage
🇷🇺 RU
TAG-28
apt_group
Information theft and espionage
🇨🇳 CN
Roaming Tiger
apt_group
Information theft and espionage
🇨🇳 CN
White Bear
apt_group
Information theft and espionage
🇷🇺 RU
Triage Info
Decided atMar 05, 2026