WHD 12.8.7 hotfix 1 release notes
Release date: September 23, 2025
Here's what's new in Web Help Desk 12.8.7 Hotfix 1.
Required actions
Last updated: September 17, 2025
Customers who downloaded and installed Web Help Desk 12.8.7 release notes should also download and install 12.8.7 Hotfix 1.
Web Help Desk 12.8.7 Hotfix 1 provides bugfixes related to CVE-2025-26399. For information about the 12.8.7 release, including EOL notices and upgrade information, see 12.8.7 Release Notes.
Learn more
- See the WHD release notes aggregator to view release notes for multiple versions of WHD on a single page.
- See the WHD 12.8.7 Hotfix 1 Administrator Guide to learn how to work with WHD.
About this hotfix
This hotfix adds or modifies the following files:
Adds file in <WebHelpDesk>/bin/webapps/helpdesk/WEB-INF/lib/ directory:
-
HikariCP.jar
Modifies <WebHelpDesk>/bin/webapps/helpdesk/WEB-INF/lib/ directory jars:
-
whd-core.jar
-
whd-web.jar
-
whd-persistence.jar
This hotfix requires Web Help Desk 12.8.7
In the installation instructions, <WebHelpDesk> represents the Web Help Desk home folder. The default home folders for the supported operating systems are listed below:
- macOS: /Library/WebHelpDesk
- Microsoft Windows: \Program Files\WebHelpDesk
- Linux: /usr/local/webhelpdesk
Install Hotfix 1
-
Stop Web Help Desk.
-
Navigate to the following directory:
-
<WebHelpDesk>/bin/webapps/helpdesk/WEB-INF/lib/
-
-
Back up the following files to a separate directory and then delete the files from the path below.
-
<WebHelpDesk>/bin/webapps/helpdesk/WEB-INF/lib/c3p0.jar
-
-
Back up the following files to a separate directory:
-
<WebHelpDesk>/bin/webapps/helpdesk/WEB-INF/lib/whd-core.jar
-
<WebHelpDesk>/bin/webapps/helpdesk/WEB-INF/lib/whd-web.jar
-
<WebHelpDesk>/bin/webapps/helpdesk/WEB-INF/lib/whd-persistence.jar
-
-
Navigate to the following directory:
-
<WebHelpDesk>/bin/webapps/helpdesk/WEB-INF/lib
-
-
Copy the files included with this hotfix to the /lib directory, overwriting the following files:
-
whd-core.jar
-
whd-web.jar
-
HikariCP.jar
-
whd-persistence.jar
-
-
Start Web Help Desk.
CVEs
Last updated: 9/16/2025
SolarWinds would like to thank our Security Researchers below for reporting on the issue in a responsible manner and working with our security, product, and engineering teams to fix the vulnerability.
SolarWinds CVEs
CVE-ID | Vulnerability Title | Description | Severity | Credit |
---|---|---|---|---|
CVE-2025-26399 | SolarWinds Web Help Desk AjaxProxy Deserialization of Untrusted Data Remote Code Execution Vulnerability | SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. This vulnerability is a patch bypass of CVE-2024-28988, which in turn is a patch bypass of CVE-2024-28986. | 9.8 Critical | Anonymous working with Trend Micro Zero Day Initiative |
Installation or upgrade
Last updated:
For new installations, you can download the installer from the SolarWinds website or from the Customer Portal. For more information, see the WHD Installation and Upgrade Guide.
-
WHD supports Windows Server 2019 and 2022 for production environments and Windows 11 for trial evaluations. These operating system require additional setup to install. See the WHD Installation and Upgrade Guide for instructions.
-
WHD no longer includes the additional configuration files required to enable Federal Information Processing Standards (FIPS) mode in the application. To install WHD and enable FIPS, see Enable FIPS in a new deployment in the WHD Administrator Guide.
For upgrades, use Upgrade WHD to plan and execute your upgrade.
-
Determine your upgrade path.
-
Download and install the upgrade package(s) from the SolarWinds Customer Portal.
-
After you have upgraded Web Help Desk, download and install any available hotfixes for this version of Web Help Desk. Hotfixes are available in the Customer Portal.
After you complete the installation, see the WHD Getting Started Guide. This guide picks up right after the installation process and walks you through the initial steps you need to take to start using the application.
Legal notices
© 2025 SolarWinds Worldwide, LLC. All rights reserved.
This document may not be reproduced by any means nor modified, decompiled, disassembled, published or distributed, in whole or in part, or translated to any electronic medium or other means without the prior written consent of SolarWinds. All right, title, and interest in and to the software, services, and documentation are and shall remain the exclusive property of SolarWinds, its affiliates, and/or its respective licensors.
SOLARWINDS DISCLAIMS ALL WARRANTIES, CONDITIONS, OR OTHER TERMS, EXPRESS OR IMPLIED, STATUTORY OR OTHERWISE, ON THE DOCUMENTATION, INCLUDING WITHOUT LIMITATION NONINFRINGEMENT, ACCURACY, COMPLETENESS, OR USEFULNESS OF ANY INFORMATION CONTAINED HEREIN. IN NO EVENT SHALL SOLARWINDS, ITS SUPPLIERS, NOR ITS LICENSORS BE LIABLE FOR ANY DAMAGES, WHETHER ARISING IN TORT, CONTRACT OR ANY OTHER LEGAL THEORY, EVEN IF SOLARWINDS HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
The SolarWinds, SolarWinds & Design, Orion, and THWACK trademarks are the exclusive property of SolarWinds Worldwide, LLC or its affiliates, are registered with the U.S. Patent and Trademark Office, and may be registered or pending registration in other countries. All other SolarWinds trademarks, service marks, and logos may be common law marks or are registered or pending registration. All other trademarks mentioned herein are used for identification purposes only and are trademarks of (and may be registered trademarks) of their respective companies.