2026-09-24 · view entry permalink →
CVE-2026-28324 / CVE-2026-28325, SolarWinds Observability Self-Hosted: two unauthenticated remote-code-execution flaws, no confirmed exploitation yet (CVSS 9.8 / 8.8)
SolarWinds released Observability Self-Hosted 2026.2.3 on 2026-09-22, fixing two unauthenticated remote-code-execution vulnerabilities that researcher Kai Huang of Armadin reported through responsible disclosure (SolarWinds, 2026-09-22). CVE-2026-28324 (CVSS 9.8) stems from insufficient integrity checks and affects installations running in a configuration SolarWinds describes only as "non-default and non-secure," without naming the specific setting (SolarWinds, 2026-09-22). CVE-2026-28325 (CVSS 8.8) is a deserialization-of-untrusted-data flaw that requires the application to be configured to use "a specific communication mode," again unnamed by the vendor (SolarWinds, 2026-09-22). The same release separately reconfigures Web Performance Monitor player communications (switching default main-polling-engine players from server-initiated to player-initiated mode and issuing newly generated passwords to remote passive players) a change significant enough that SolarWinds frames it as a "critical update advisory" in its own right; SolarWinds does not state that this reconfiguration is connected to either CVE (SolarWinds, 2026-09-22).
Both NCSC-NL and CERT-FR flagged the advisory the day after release, and neither adds technical detail beyond what SolarWinds published (NCSC-NL, 2026-09-23; CERT-FR, 2026-09-23). "SolarWinds has not provided technical exploit details, affected endpoint information, or evidence of active exploitation in the release notes" (GBHackers, 2026-09-23), no vendor, national CERT or researcher source reports in-the-wild exploitation or a public proof-of-concept as of this writing. Unauthenticated code execution against internet-reachable network-monitoring infrastructure is nonetheless a high-value initial-access target regardless of confirmed exploitation status today.
SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability due to the insufficient integrity checks. Installations configured in a non-default and non-secure configuration are affected.
SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability stemming from deserialization of untrusted data when the application is configured to use a specific communication mode.
SolarWinds has not provided technical exploit details, affected endpoint information, or evidence of active exploitation in the release notes.