Skip to content
TrustList
News

SolarWinds fixes two critical remote-code flaws in Observability Self-Hosted

Editorial

By TrustList Editorial

CVE-2026-28324 (9.8) and CVE-2026-28325 (8.8) allow unauthenticated code execution in some SolarWinds Observability Self-Hosted configurations. Version 2026.2.3 fixes both; no attacks are reported yet.

About SolarWinds fixes two critical remote-code flaws in Observability Self-Hosted

SolarWinds fixes two critical remote-code flaws in Observability Self-Hosted

22 September 2026 — SolarWinds published two security advisories on 22 September 2026 for SolarWinds Observability Self-Hosted, the on-premises version of its infrastructure and application monitoring. Both flaws let an attacker run code without logging in, in certain configurations. Version 2026.2.3 fixes both. SolarWinds reports no exploitation so far, and SecurityWeek covered the fixes on 24 September.

The two flaws

  • CVE-2026-28324, rated 9.8 out of 10: remote code execution caused by insufficient integrity checks. SolarWinds says it affects installations in a "non-default and non-secure configuration".
  • CVE-2026-28325, rated 8.8: remote code execution through deserialisation of untrusted data, when a specific communication mode is configured. The attacker must be on an adjacent network, which lowers the risk but does not remove it for a monitoring server that sits on internal networks by design.

Both affect version 2026.2.2 and earlier. The researcher credited is Kai Huang of Armadin.

Why monitoring servers matter

A monitoring platform usually holds credentials for the systems it watches and can reach most of the network, which is why attackers target it. SolarWinds products have a history as targets, so a fix with no known exploitation is the cheapest moment to act. The week before, SolarWinds also fixed CVE-2026-28326, a hardcoded key in Access Rights Manager, SecurityWeek reported.

Who is affected

Organisations that run SolarWinds Observability Self-Hosted for on-premises or hybrid monitoring, and customers of managed service providers that run it on their behalf. The cloud (software-as-a-service) edition is not named in the advisories.

What to do

  • Upgrade to 2026.2.3.
  • Check whether your deployment uses a non-default configuration or the communication mode named in the advisory, so you know whether you were exposed before patching.
  • Review the credentials the monitoring server holds and who can reach it on the network.
  • If a managed provider runs SolarWinds for you, ask when it will upgrade and whether it uses the affected configuration.

Sources