Vulnerabilities & Exploits

SolarWinds Fixes Two Unauthenticated RCE Flaws

SolarWinds and national CERTs disclosed two unauthenticated remote code execution flaws in Observability Self-Hosted and shipped version 2026.2.3 to fix them. One is tracked as CVE-2026-28324, the other as CVE-2026-28325.

One bug comes from deserializing untrusted data in a specific communication mode, which can turn attacker-controlled data into code the server runs. The other is an insufficient integrity check that only affects non-default, insecure configurations, so not every deployment carries the same exposure.

For operators, the important distinction is that this is not just a generic default-install patch story: systems configured outside the secure path can remain vulnerable even when the product is otherwise current. If SolarWinds Observability Self-Hosted sits in front of management functions, a hit on the platform can become full server takeover.

4 sources · 10h ago

CVE-2026-28324

NVD KEV

CVSS 9.8 CRITICAL: solarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability due to the insufficient integrity checks.

CVE-2026-28325

NVD KEV

CVSS 8.8 HIGH: solarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution…

Timeline

Sources

Part of the PlainSec briefing for 2026-09-24

Every edition of this story: SolarWinds Fixes Two Unauthenticated RCE Flaws

More from today