Skip to content
feed: live
>_0dayNews
solarwinds

SolarWinds Fixes Two Unauth RCE Flaws in Observability

SolarWinds patches CVE-2026-28324 (CVSS 9.8) and CVE-2026-28325 (CVSS 8.8), two unauthenticated RCE flaws in Observability Self-Hosted. No active exploitation reported.

SolarWinds Fixes Two Unauth RCE Flaws in Observability
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
kilobaudDave "Kilobaud" Ferris·Published ·1 min read

SolarWinds has patched two unauthenticated RCE vulnerabilities in Observability Self-Hosted, both published to NVD on September 22 and reported by SecurityWeek.

CVE-2026-28324 (CVSS 9.8, critical): Unauthenticated RCE via insufficient integrity checks. NVD scope note: only affects installations configured in a “non-default and non-secure configuration.”

CVE-2026-28325 (CVSS 8.8, high): Unauthenticated RCE via deserialization of untrusted data. Only triggered when the application uses a specific communication mode. NVD entry.

No active exploitation has been reported for either CVE at time of publication.

Analysis: The scope qualifiers deserve more than a quick scan. “Non-default and non-secure configuration” for CVE-2026-28324 and “a specific communication mode” for CVE-2026-28325 are both real constraints, and they are also the kind of constraints that apply to many production deployments. Enterprise monitoring tools get configured; over months and years, those configurations diverge from whatever the secure defaults were at install. An organization that has not reviewed its Observability Self-Hosted configuration recently is in an unknown state against both CVEs, not an out-of-scope one.

SolarWinds patched a separate unauthenticated RCE last week: CVE-2026-28326 (CVSS 8.8) in Access Rights Manager, a hardcoded-credential flaw in a different product line.

Related CVEs
  • [ CRITICAL ]CVE-2026-28324SolarWinds Observability Self-Hosted Unauth RCE
  • [ HIGH ]CVE-2026-28325SolarWinds Observability Self-Hosted RCE via Deserialization

Found this useful? Share it.