← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 23, 2026 · 11:19via CyberPress

SolarWinds Observability Flaws Let Unauthenticated Attackers Execute Remote Code

Brief

SolarWinds released Observability Self-Hosted 2026.

  • 3 to address two critical remote code execution vulnerabilities that could let unauthenticated attackers compromise affected deployments.

The flaws, tracked as CVE-2026-28324 and CVE-2026-28325, carry CVSS severity scores of 9. 8 and 8. 8, respectively, and security researcher Kai Huang of Armadin reported them.

SolarWinds said both vulnerabilities affect deployments operating under specific non-default communication or configuration conditions, making configuration reviews as important as applying the available update.

SolarWinds Observability Flaws

CVE-2026-28324 is a critical remote code execution vulnerability with a CVSS score of 9.

  • According to SolarWinds, the issue stems from insufficient integrity checks in SolarWinds Observability Self-Hosted.
Read more on CyberPress