SolarWinds security advisory (AV26-950)
Canadian Cyber Centre advisory warns of unauthenticated and authenticated RCE flaws in SolarWinds Observability Self-Hosted.
The Canadian Centre for Cyber Security has issued an advisory for SolarWinds Observability Self-Hosted, warning of two Remote Code Execution vulnerabilities. CVE-2026-28325 is an unauthenticated RCE flaw, while CVE-2026-28324 is an authenticated RCE vulnerability. Users are advised to update to version 2026.2.3 or later to mitigate these security risks.
- SolarWinds Observability Self-Hosted is affected by unauthenticated and authenticated RCE flaws.
- CVE-2026-28325 is an unauthenticated Remote Code Execution vulnerability.
- The Canadian Cyber Centre urges users to apply updates to version 2026.2.3 or later.
Vulnerabilities mentionedAll →
- CVE-2026-283249.8—SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability due to the insufficient integrity checkspublished
- CVE-2026-283258.8—SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability stemming from deserialization of…published
| CVE | Vulnerability | CVSS | EPSS | Flags |
|---|
Full article69 words · extracted from cyber.gc.ca · click to collapse
Serial number: AV26-950
Date: September 23, 2026
As of September 22, 2026, SolarWinds is affected by vulnerabilities in the following product:
- SolarWinds Observability Self-Hosted
- Prior to 2026.2.3
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/solarwinds-security-advisory-av26-950