SolarWinds Patches Critical RCE Flaws in Observability Self-Hosted
SolarWinds patched two unauthenticated RCE flaws in Observability Self-Hosted, with no exploitation reported.
SolarWinds patched two unauthenticated remote code execution flaws in Observability Self-Hosted, affecting all versions through 2026.2.2 and fixed in 2026.2.3. CVE-2026-28324 (CVSS 9.8) is an insufficient integrity check on non-default, non-secure configurations, and CVE-2026-28325 (CVSS 8.8) is deserialization of untrusted data when a specific communication mode is used. The company also recently fixed CVE-2026-28326 (CVSS 8.8), a hardcoded static key in Access Rights Manager through version 2026.2. SolarWinds said none of these defects are known to be exploited and credited Kai Huang of Armadin for the Observability reports.