Critical SolarWinds Flaws Let Attackers Remotely Execute Code on Observability Servers
SolarWinds patches critical CVEs allowing unauthenticated RCE on Observability Self-Hosted servers in non-default configs.
SolarWinds has released Observability Self-Hosted 2026.2.3 to patch two critical vulnerabilities that allow unauthenticated attackers to remotely execute code. CVE-2026-28324, rated 9.8, is due to insufficient integrity checks in non-default, non-secure configurations, while CVE-2026-28325 (8.8) is caused by unsafe deserialization in specific communication modes. The vulnerabilities affect deployments using Web Performance Monitor (WPM) players, and SolarWinds has ended support for older versions like 2024.2.
- SolarWinds patches two critical flaws (CVE-2026-28324, CVE-2026-28325) allowing unauthenticated remote code execution.
- CVE-2026-28324 has a CVSS score of 9.8 and stems from insufficient integrity checks in non-default configurations.
- CVE-2026-28325 (CVSS 8.8) involves unsafe deserialization of untrusted data in specific communication modes.
- Patches are in Observability Self-Hosted 2026.2.3; older versions like 2024.2 are no longer supported.
Vulnerabilities mentionedAll →
- CVE-2026-283249.8—SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability due to the insufficient integrity checkspublished
- CVE-2026-283258.8—SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability stemming from deserialization of…published
| CVE | Vulnerability | CVSS | EPSS | Flags |
|---|
Full article494 words · extracted from cybersecuritynews.com · click to collapse
SolarWinds released Observability Self-Hosted 2026.2.3 to fix two serious vulnerabilities that could let unauthenticated attackers remotely execute code on affected observability servers. The flaws, tracked as CVE-2026-28324 and CVE-2026-28325, affect specific non-default configurations and communication modes.
The update was released on September 22, 2026, and is especially important for organizations running SolarWinds Observability Self-Hosted in environments with Web Performance Monitor, or WPM, players.
Successful exploitation could let a remote attacker run arbitrary commands on a vulnerable server without logging in first. CVE-2026-28324 is rated 9.8 out of 10 on the CVSS severity scale, making it a critical issue.
SolarWinds said the vulnerability stems from insufficient integrity checks in Observability Self-Hosted installations configured in a non-default, non-secure manner.
SolarWinds Flaws Execute Code
The advisory does not provide public proof-of-concept details. However, the high severity score indicates that defenders should treat exposed and specially configured servers as high-priority patching targets. The second flaw, CVE-2026-28325, has a CVSS score of 8.8 and is also classified as an unauthenticated remote code execution issue.
According to SolarWinds, it stems from deserializing untrusted data when the application uses a specific communication mode. Unsafe deserialization occurs when software accepts attacker-controlled serialized data and processes it without proper validation, potentially allowing malicious objects or commands to run in the application context.
Kai Huang of Armadin responsibly reported both vulnerabilities. SolarWinds said the issues are resolved in version 2026.2.3, which adds no new product features but includes security fixes and platform reliability improvements.
The release also changes the behavior of certain WPM player deployments. After the upgrade, passive WPM players installed by default on the main polling engine are switched from server-initiated to player-initiated communication.
Remote passive WPM players are automatically assigned randomly generated strong passwords during their upgrade. However, SolarWinds noted that players with the Enable Upgrade option disabled are not upgraded automatically and require administrator attention. Active, player-initiated WPM players do not require a password after the upgrade.
Administrators should upgrade their entire SolarWinds deployment through Settings > My Deployment, which updates SolarWinds Platform products and related scalability engines.
Before applying the update, security teams should identify all main polling engines, remote WPM players, and communication modes in use.
They should also verify that passive remote players have strong credentials and that systems excluded from automatic upgrades are updated manually.
Organizations should review server exposure, restrict management access to trusted networks, monitor SolarWinds application and Windows logs for unexpected process execution, and investigate abnormal activity involving polling engines or WPM players.
Older deployments deserve particular attention: SolarWinds has ended engineering support for Observability Self-Hosted 2024.2 and earlier versions, meaning they no longer receive regular fixes or service releases.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Abinayahttps://cybersecuritynews.com/
Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.