CTIPilot
← Back to the live brief
HIGHCVE-2026-28324 +1NATOA2vulnerability

CVE-2026-28324 / CVE-2026-28325, SolarWinds Observability Self-Hosted: two unauthenticated remote-code-execution flaws, no confirmed exploitation yet (CVSS 9.8 / 8.8)

SolarWinds patches two unauthenticated RCE flaws in its self-hosted monitoring platform

Defender actions

  • Upgrade every SolarWinds Observability Self-Hosted deployment to 2026.2.3 via Settings > My Deployment now; before or during the upgrade, audit which Web Performance Monitor players and other SolarWinds services are internet-reachable, and confirm no deployment is running the communication-mode or integrity-check configuration the advisory calls non-default and non-secure.

Analysis

SolarWinds released Observability Self-Hosted 2026.2.3 on 2026-09-22, fixing two unauthenticated remote-code-execution vulnerabilities that researcher Kai Huang of Armadin reported through responsible disclosure (SolarWinds, 2026-09-22). CVE-2026-28324 (CVSS 9.8) stems from insufficient integrity checks and affects installations running in a configuration SolarWinds describes only as "non-default and non-secure," without naming the specific setting (SolarWinds, 2026-09-22). CVE-2026-28325 (CVSS 8.8) is a deserialization-of-untrusted-data flaw that requires the application to be configured to use "a specific communication mode," again unnamed by the vendor (SolarWinds, 2026-09-22). The same release separately reconfigures Web Performance Monitor player communications (switching default main-polling-engine players from server-initiated to player-initiated mode and issuing newly generated passwords to remote passive players) a change significant enough that SolarWinds frames it as a "critical update advisory" in its own right; SolarWinds does not state that this reconfiguration is connected to either CVE (SolarWinds, 2026-09-22).

Both NCSC-NL and CERT-FR flagged the advisory the day after release, and neither adds technical detail beyond what SolarWinds published (NCSC-NL, 2026-09-23; CERT-FR, 2026-09-23). "SolarWinds has not provided technical exploit details, affected endpoint information, or evidence of active exploitation in the release notes" (GBHackers, 2026-09-23), no vendor, national CERT or researcher source reports in-the-wild exploitation or a public proof-of-concept as of this writing. Unauthenticated code execution against internet-reachable network-monitoring infrastructure is nonetheless a high-value initial-access target regardless of confirmed exploitation status today.

Cited evidence

SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability due to the insufficient integrity checks. Installations configured in a non-default and non-secure configuration are affected.

SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability stemming from deserialization of untrusted data when the application is configured to use a specific communication mode.

SolarWinds

SolarWinds has not provided technical exploit details, affected endpoint information, or evidence of active exploitation in the release notes.

GBHackers 2026-09-23

Sources4

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.