
Detection for CVE-2025-26399
This script detects SolarWinds Web Help Desk instances vulnerable to CVE-2025-26399 by requesting the Helpdesk login page, confirming product identifiers in the response, extracting the embedded build token as a version string, and flagging systems running versions earlier than 12.8.7.0.
nuclei -u https://yourHost.com -t template.yamlUse at your own risk, I will not be responsible for illegal activities you conduct on infrastructure you do not own or have permission to scan.
Feel free to reach out via Signal if you have any questions.