Exploits using legitimate tools
On February 9, 2026, Bleeping Computer revealed that attackers were exploiting critical vulnerabilities in SolarWinds Web Help Desk (WHD). The flaws let them gain remote-code execution without logging in.
Two vulnerabilities were involved: CVE-2025-40551 and CVE-2025-26399. Both allowed remote attackers to run arbitrary code with no authentication required.
Once inside, the intruders relied on legitimate administration tools to stay hidden. They installed Zoho ManageEngine Assist for remote access. They opened Cloudflare tunnels for persistence. And they used Velociraptor, a digital-forensics tool, as their command-and-control channel. Because these tools are signed and widely used, the attackers blended into normal IT activity.
The campaign began around January 16 - just days after SolarWinds published patches. It has affected at least three organizations so far.
This isn't the first time SolarWinds has been at the center of a major attack. The 2020 supply-chain breach still looms large. The WHD exploitation reinforces a familiar pattern: attackers keep probing widely used tools for weaknesses, and they strike fast once a flaw appears - especially when they can hide behind legitimate software.
Security researchers have documented other cases where Velociraptor was abused to open tunnels to attacker servers. This points to a broader trend: adversaries are increasingly leveraging legitimate DFIR and remote-management software to blend in. That trend makes one thing clear - timely remediation matters just as much as detection, if not more.
Understanding the vulnerabilities
SolarWinds WHD is a ticketing and asset-management system used by IT teams worldwide. In late January 2026, SolarWinds disclosed several critical vulnerabilities in the platform.
Security vendors noted that two of these flaws allow unauthenticated remote-code execution through unsafe deserialization. Others allow attackers to bypass authentication entirely. Version 2026.1 patches all known issues.
CISA added CVE-2025-40551 to its Known Exploited Vulnerabilities list on February 3, 2026. By February 7, active exploitation was already underway.
Here's what makes unauthenticated RCE so dangerous: simply exposing WHD to the internet gives attackers a way in. Once an exploit runs, they can deploy legitimate remote-management tools and pivot deeper into the network - often without triggering any alarms.

Lessons from SolarWinds: the remediation gap
The WHD exploitation isn't just a story about one vendor. It's a symptom of a much bigger problem: the remediation gap in vulnerability management overall.
Traditional workflows prioritize detection over action. Scanners generate thousands of findings and tickets, but remediation is treated as a separate process - one that requires approvals and change windows. As a result, patches can take weeks to apply. Mean time to remediate often stretches to 60-120 days, while attackers weaponize new vulnerabilities within days of disclosure.
Most organizations rely on multiple disconnected tools for scanning and patching. That fragmentation lets vulnerabilities in smaller applications linger - and those overlooked apps become easy entry points for attackers.
This gap didn't appear overnight. It's rooted in how vulnerability management evolved. Early scanners were praised for their comprehensiveness, but that strength came with a cost: teams were flooded with thousands of findings while patching remained slow and manual. The result was a growing backlog that aged in ticket queues. Third-party software made the problem worse, since each program came with its own separate update mechanism.
Vicarius and the remediation-first philosophy
Vicarius approaches the problem from the opposite direction: start with remediation, then build detection around it.
The vRx platform unifies discovery, prioritization, and remediation into a single workflow. This eliminates the handoff to separate patch-management tools that slows so many organizations down.
Instead of generating long lists of findings and expecting teams to fix them manually, vRx treats remediation as the core function. It discovers vulnerabilities, assesses their risk, and fixes them - through automated patches, configuration scripts, or protective controls when a vendor patch isn't available yet.
Three ways to fix vulnerabilities
- Native patching automates the deployment of vendor patches across more than 10,000 operating systems and third-party applications.
- Scripting addresses exposures that require configuration changes or custom remediation steps.
- Patchless Protection provides temporary shielding when no patch exists yet, reducing exploitability until one can be safely applied.
Intelligent prioritization and scalability
No organization can fix every vulnerability at once. That's why vRx uses contextual intelligence to decide what to address first.
The platform weighs CVSS severity, EPSS exploitation likelihood, KEV status, and asset criticality together. A critical flaw on an internet-facing production server outranks the same flaw on an isolated development host. This context-driven approach cuts through the noise that plagues legacy scanners.
vRx is also built for multi-tenant environments. Managed service providers can manage multiple clients from a single interface, while still maintaining data separation and automating routine tasks across many customers at once. A built-in compliance engine tracks alignment with frameworks like CIS and PCI DSS, among others.
Organizations adopting this model report significant drops in both mean time to remediate and overall patch-management workload.
Unified remediation also simplifies compliance. Modern frameworks such as PCI DSS, HIPAA, and CIS Controls all require vulnerability awareness and proof of timely remediation. When discovery, prioritization, and remediation happen in the same system, audit reports generate automatically - the platform already knows when a vulnerability was found, what action was taken, and when it was completed.
This reduces administrative overhead for security teams. It also gives regulators and insurers clear evidence that the organization is actively closing exposures, not just tracking them.

Critical reflections and forward-looking ideas
The WHD incident shows that patching alone is necessary, but not sufficient. Even after upgrading to version 2026.1, administrators were advised to restrict WHD's internet exposure and reset credentials.
Attackers had abused an outdated version of Velociraptor in this campaign. That's a reminder that defenders need to secure their entire application ecosystem - not just the core platform, but remote-management agents and DFIR tools too.
Adversaries are increasingly turning to signed software like Zoho Assist, Cloudflare tunneling, and Velociraptor to avoid detection. Antivirus solutions rarely flag these installations, since the tools themselves are legitimate. A strong remediation platform should watch for unexpected deployments of legitimate tools, enforce policies that block unauthorized software, and quickly restore any disabled security services.
The window between disclosure and exploitation keeps shrinking. In the WHD case, active attacks were observed within about ten days of disclosure. Organizations can no longer afford to wait for monthly patch windows - continuous remediation is essential.
Applying patches as soon as they're validated, and using patchless protection when a vendor fix isn't available, narrows the window of exposure significantly. Eliminating the handoff between security and IT teams matters just as much. When the same platform identifies a vulnerable WHD installation and deploys the necessary update, delays simply disappear. Patchless protection also offers immediate mitigation for zero-day flaws, reducing risk while a permanent fix is developed.
Final thoughts: the real measure of security
The SolarWinds WHD exploitation is a reminder that security is measured by vulnerabilities removed, not vulnerabilities found. Attackers weaponized a newly disclosed flaw within ten days, then used legitimate tools to hide in plain sight.
Traditional vulnerability management - the kind that emphasizes detection and reporting over action - leaves organizations exposed, because it doesn't ensure timely fixes. The remediation gap is exactly where attackers operate.
Vicarius's remediation-first approach offers a blueprint for closing that gap. By unifying discovery, prioritization, and remediation - and combining automated patching across thousands of applications with scripting for complex fixes, patchless protection for unpatched flaws, and prioritization based on real risk - vRx turns vulnerability management into vulnerability elimination.
Real-world results back this up: organizations report dramatic reductions in both mean time to remediate and operational overhead. This is more than theory. It's a practical path toward resilience.
The next time a zero-day flaw is disclosed, the critical question won't be "Do we see it?" It will be "How fast can we fix it?" The future belongs to those who can answer that question with speed and confidence.
Related resources:
CVE research















.webp)







































%20Signals%20a%20New%20Era%20of%20Supply%20Chain%20Risk.webp)












.webp)























%20to%20Reduce%20Attack%20Surface.avif)



.avif)







