CVE-2026-28324
CVSS 9.8 CRITICAL: solarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability due to the insufficient integrity checks.
Vulnerabilities & Exploits
SolarWinds and national CERTs disclosed two unauthenticated remote code execution flaws in Observability Self-Hosted and shipped version 2026.2.3 to fix them. One is tracked as CVE-2026-28324, the other as CVE-2026-28325.
One bug comes from deserializing untrusted data in a specific communication mode, which can turn attacker-controlled data into code the server runs. The other is an insufficient integrity check that only affects non-default, insecure configurations, so not every deployment carries the same exposure.
For operators, the important distinction is that this is not just a generic default-install patch story: systems configured outside the secure path can remain vulnerable even when the product is otherwise current. If SolarWinds Observability Self-Hosted sits in front of management functions, a hit on the platform can become full server takeover.
4 sources · 10h ago
CVSS 9.8 CRITICAL: solarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability due to the insufficient integrity checks.
CVSS 8.8 HIGH: solarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution…
SecurityWeek
SolarWinds Patches Critical RCE Flaws in Observability Self-Hosted
The vulnerabilities, tracked as CVE-2026-28324 and CVE-2026-28325, can be exploited without authentication.
originalCSIRT Italia / ACN
Vulnerabilità in prodotti SolarWinds
Aggiornamenti di sicurezza SolarWinds sanano 2 vulnerabilità, di cui 1 con gravità "critica" e 1 con gravità "alta", presenti in Observability Self-Hosted, piattaforma per il monitoraggio e l'osservabilità delle infrastrutture e delle applicazioni.
originalNCSC-NL Advisories
Kwetsbaarheden verholpen in SolarWinds Observability Self-Hosted
SolarWinds heeft kwetsbaarheden verholpen in SolarWinds Observability Self-Hosted.
originalPart of the PlainSec briefing for 2026-09-24
Every edition of this story: SolarWinds Fixes Two Unauthenticated RCE Flaws