SolarWinds fixes two critical remote-code flaws in Observability Self-Hosted
EditorialBy TrustList Editorial
CVE-2026-28324 (9.8) and CVE-2026-28325 (8.8) allow unauthenticated code execution in some SolarWinds Observability Self-Hosted configurations. Version 2026.2.3 fixes both; no attacks are reported yet.
About SolarWinds fixes two critical remote-code flaws in Observability Self-Hosted
SolarWinds fixes two critical remote-code flaws in Observability Self-Hosted
22 September 2026 — SolarWinds published two security advisories on 22 September 2026 for SolarWinds Observability Self-Hosted, the on-premises version of its infrastructure and application monitoring. Both flaws let an attacker run code without logging in, in certain configurations. Version 2026.2.3 fixes both. SolarWinds reports no exploitation so far, and SecurityWeek covered the fixes on 24 September.
The two flaws
- CVE-2026-28324, rated 9.8 out of 10: remote code execution caused by insufficient integrity checks. SolarWinds says it affects installations in a "non-default and non-secure configuration".
- CVE-2026-28325, rated 8.8: remote code execution through deserialisation of untrusted data, when a specific communication mode is configured. The attacker must be on an adjacent network, which lowers the risk but does not remove it for a monitoring server that sits on internal networks by design.
Both affect version 2026.2.2 and earlier. The researcher credited is Kai Huang of Armadin.
Why monitoring servers matter
A monitoring platform usually holds credentials for the systems it watches and can reach most of the network, which is why attackers target it. SolarWinds products have a history as targets, so a fix with no known exploitation is the cheapest moment to act. The week before, SolarWinds also fixed CVE-2026-28326, a hardcoded key in Access Rights Manager, SecurityWeek reported.
Who is affected
Organisations that run SolarWinds Observability Self-Hosted for on-premises or hybrid monitoring, and customers of managed service providers that run it on their behalf. The cloud (software-as-a-service) edition is not named in the advisories.
What to do
- Upgrade to 2026.2.3.
- Check whether your deployment uses a non-default configuration or the communication mode named in the advisory, so you know whether you were exposed before patching.
- Review the credentials the monitoring server holds and who can reach it on the network.
- If a managed provider runs SolarWinds for you, ask when it will upgrade and whether it uses the affected configuration.
Sources
- SolarWinds Trust Center: CVE-2026-28324 — 22 September 2026
- SolarWinds Trust Center: CVE-2026-28325 — 22 September 2026
- SecurityWeek: SolarWinds patches critical RCE flaws in Observability Self-Hosted — 24 September 2026
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.