← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 23, 2026 · 08:15via Cyber Security News

Critical SolarWinds Flaws Let Attackers Remotely Execute Code on Observability Servers

Brief

SolarWinds released Observability Self-Hosted 2026.

  • 3 to fix two serious vulnerabilities that could let unauthenticated attackers remotely execute code on affected observability servers . The flaws, tracked as CVE-2026-28324 and CVE-2026-28325, affect specific non-default configurations and communication modes.

The update was released on September 22, 2026, and is especially important for organizations running SolarWinds Observability Self-Hosted in environments with Web Performance Monitor, or WPM, players.

Successful exploitation could let a remote attacker run arbitrary commands on a vulnerable server without logging in first. CVE-2026-28324 is rated 9. 8 out of 10 on the CVSS severity scale, making it a critical issue.

Read more on Cyber Security News