CTIPilot

SolarWinds Observability Self-Hosted: unauthenticated RCE via insufficient integrity checks (CVSS 9.8), no confirmed exploitation

cve · CVE-2026-28324

Coverage timeline
1
first 2026-09-24 → last 2026-09-24
Peak priority
high
1 high
Sources cited
4
4 hosts
Sections touched
1
trending-vulnerabilities
Co-occurring entities
2
see Co-occurring entities below
ATT&CK techniques
1
pinned v19.2 · see below

ATT&CK techniques

1 technique observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-09-24/solarwinds-observability-cve-2026-28324-28325-unauth-rce · ATT&CK page ↗

Story timeline

  1. 2026-09-24CVE-2026-28324 / CVE-2026-28325, SolarWinds Observability Self-Hosted: two unauthenticated remote-code-execution flaws, no confirmed exploitation yet (CVSS 9.8 / 8.8)
    trending-vulnerabilitiesSolarWinds patches two unauthenticated RCE flaws in its self-hosted monitoring platform

Where this entity is cited

  • trending-vulnerabilities1

Source distribution

  • advisories.ncsc.nl1 (25%)
  • cert.ssi.gouv.fr1 (25%)
  • documentation.solarwinds.com1 (25%)
  • gbhackers.com1 (25%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about SolarWinds Observability Self-Hosted: unauthenticated RCE via insufficient integrity checks (CVSS 9.8), no confirmed exploitation (1)

2026-09-24 · view entry permalink →

CVE-2026-28324 / CVE-2026-28325, SolarWinds Observability Self-Hosted: two unauthenticated remote-code-execution flaws, no confirmed exploitation yet (CVSS 9.8 / 8.8)

SolarWinds released Observability Self-Hosted 2026.2.3 on 2026-09-22, fixing two unauthenticated remote-code-execution vulnerabilities that researcher Kai Huang of Armadin reported through responsible disclosure (SolarWinds, 2026-09-22). CVE-2026-28324 (CVSS 9.8) stems from insufficient integrity checks and affects installations running in a configuration SolarWinds describes only as "non-default and non-secure," without naming the specific setting (SolarWinds, 2026-09-22). CVE-2026-28325 (CVSS 8.8) is a deserialization-of-untrusted-data flaw that requires the application to be configured to use "a specific communication mode," again unnamed by the vendor (SolarWinds, 2026-09-22). The same release separately reconfigures Web Performance Monitor player communications (switching default main-polling-engine players from server-initiated to player-initiated mode and issuing newly generated passwords to remote passive players) a change significant enough that SolarWinds frames it as a "critical update advisory" in its own right; SolarWinds does not state that this reconfiguration is connected to either CVE (SolarWinds, 2026-09-22).

Both NCSC-NL and CERT-FR flagged the advisory the day after release, and neither adds technical detail beyond what SolarWinds published (NCSC-NL, 2026-09-23; CERT-FR, 2026-09-23). "SolarWinds has not provided technical exploit details, affected endpoint information, or evidence of active exploitation in the release notes" (GBHackers, 2026-09-23), no vendor, national CERT or researcher source reports in-the-wild exploitation or a public proof-of-concept as of this writing. Unauthenticated code execution against internet-reachable network-monitoring infrastructure is nonetheless a high-value initial-access target regardless of confirmed exploitation status today.

SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability due to the insufficient integrity checks. Installations configured in a non-default and non-secure configuration are affected.

SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability stemming from deserialization of untrusted data when the application is configured to use a specific communication mode.

SolarWinds

SolarWinds has not provided technical exploit details, affected endpoint information, or evidence of active exploitation in the release notes.

GBHackers 2026-09-23
vulnerability24 Sep 04:35Zmulti-sourceOpen finding ↗