SolarWinds patches two critical Observability Self-Hosted RCE flaws
SolarWinds fixed two critical Observability Self-Hosted RCE bugs in 2026.2.3; sources disagree on whether one needs authentication, and no exploitation is reported.
SolarWinds released Observability Self-Hosted 2026.2.3 on September 22, 2026, fixing CVE-2026-28324 (CVSS 9.8), tied to insufficient integrity checks in non-default, non-secure configurations, and CVE-2026-28325 (CVSS 8.8), unsafe deserialization of untrusted data in a specific communication mode. Cyber Security News, GBHackers, SecurityWeek, and WIRED describe both as unauthenticated remote code execution, but Canadian Centre for Cyber Security advisory AV26-950 treats CVE-2026-28324 as authenticated RCE while still calling CVE-2026-28325 unauthenticated. SecurityWeek says the Observability bugs affect all versions through 2026.2.2 and are fixed in 2026.2.3, whereas WIRED says they affect versions up to 2026.2.3; the Canadian Centre urges 2026.2.3 or later, and Cyber Security News says support has ended for older versions such as 2024.2. Both issues require non-default or specific communication configurations, affect deployments using Web Performance Monitor players, and were reported by Kai Huang of Armadin, with no active exploitation reported. Separately, SecurityWeek says SolarWinds also fixed CVE-2026-28326 (CVSS 8.8), a hardcoded static key in Access Rights Manager through version 2026.2, which is also not known to be exploited. GBHackers advises upgrading via Settings > My Deployment and segmenting or de-exposing SolarWinds services in the meantime.
- SolarWinds released Observability Self-Hosted 2026.2.3 on September 22, 2026, patching two critical RCE flaws.
- CVE-2026-28324 (CVSS 9.8) is an insufficient integrity check in non-default, non-secure configurations; Cyber Security News, GBHackers, SecurityWeek, and WIRED call it unauthenticated RCE, while Canadian Centre advisory AV26-950 calls it…
- CVE-2026-28325 (CVSS 8.8) is unauthenticated RCE from unsafe deserialization of untrusted data in a specific communication mode, per all sources that describe it.
- SecurityWeek says both affect Observability Self-Hosted through 2026.2.2 and are fixed in 2026.2.3; WIRED says they affect versions up to 2026.2.3; the Canadian Centre advises 2026.2.3 or later, and Cyber Security News says support ended…
- The flaws require non-default or specific communication-mode configurations and affect deployments using Web Performance Monitor (WPM) players.
- Kai Huang of Armadin reported the Observability issues; SolarWinds and covering outlets say no active exploitation is known.
- SecurityWeek also reports CVE-2026-28326 (CVSS 8.8), a hardcoded static key in Access Rights Manager through version 2026.2, likewise not known to be exploited.
- GBHackers says to upgrade via Settings > My Deployment and to segment or reduce exposure of SolarWinds services.
Coverage timelineoldest first · each row is one article
- · 3d agoCritical SolarWinds Flaws Let Attackers Remotely Execute Code on Observability Servers
Cyber Security News· 65
SolarWinds patches critical CVEs allowing unauthenticated RCE on Observability Self-Hosted servers in non-default configs.
- · 3d agoSolarWinds Observability Flaws Let Unauthenticated Attackers Execute Remote Code
GBHackers· 62
SolarWinds patched two unauthenticated RCE flaws in Observability Self-Hosted 2026.2.3; CVE-2026-28324 scores CVSS 9.8, CVE-2026-28325 scores 8.8, no exploitation reported.
- · 3d agoSolarWinds security advisory (AV26-950)
Canadian Centre for Cyber Security· 45
Vulnerabilities in this storyAll →
- CVE-2026-283249.8—SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability due to the insufficient integrity checkspublished
- CVE-2026-283258.8—SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability stemming from deserialization of…published