SolarWinds security advisory (AV26-950)
Canadian Cyber Centre advisory warns of unauthenticated and authenticated RCE flaws in SolarWinds Observability Self-Hosted.
The Canadian Centre for Cyber Security has issued an advisory for SolarWinds Observability Self-Hosted, warning of two Remote Code Execution vulnerabilities. CVE-2026-28325 is an unauthenticated RCE flaw, while CVE-2026-28324 is an authenticated RCE vulnerability. Users are advised to update to version 2026.2.3 or later to mitigate these security risks.