SolarWinds Fixes Two Unauth RCE Flaws in Observability
SolarWinds patches CVE-2026-28324 (CVSS 9.8) and CVE-2026-28325 (CVSS 8.8), two unauthenticated RCE flaws in Observability Self-Hosted. No active exploitation reported.

SolarWinds has patched two unauthenticated RCE vulnerabilities in Observability Self-Hosted, both published to NVD on September 22 and reported by SecurityWeek.
CVE-2026-28324 (CVSS 9.8, critical): Unauthenticated RCE via insufficient integrity checks. NVD scope note: only affects installations configured in a “non-default and non-secure configuration.”
CVE-2026-28325 (CVSS 8.8, high): Unauthenticated RCE via deserialization of untrusted data. Only triggered when the application uses a specific communication mode. NVD entry.
No active exploitation has been reported for either CVE at time of publication.
Analysis: The scope qualifiers deserve more than a quick scan. “Non-default and non-secure configuration” for CVE-2026-28324 and “a specific communication mode” for CVE-2026-28325 are both real constraints, and they are also the kind of constraints that apply to many production deployments. Enterprise monitoring tools get configured; over months and years, those configurations diverge from whatever the secure defaults were at install. An organization that has not reviewed its Observability Self-Hosted configuration recently is in an unknown state against both CVEs, not an out-of-scope one.
SolarWinds patched a separate unauthenticated RCE last week: CVE-2026-28326 (CVSS 8.8) in Access Rights Manager, a hardcoded-credential flaw in a different product line.
- [ CRITICAL ]CVE-2026-28324SolarWinds Observability Self-Hosted Unauth RCE
- [ HIGH ]CVE-2026-28325SolarWinds Observability Self-Hosted RCE via Deserialization
Found this useful? Share it.
