Skip to content
feed: live
>_0dayNews
CVE Record
[ HIGH ]CVE-2026-28325

SolarWinds Observability Self-Hosted RCE via Deserialization

CVSS 8.8 high. Unauthenticated RCE through deserialization of untrusted data in SolarWinds Observability Self-Hosted when using a specific communication mode.

cat cve-2026-28325.json
Vendor
SolarWinds
Product
Observability Self-Hosted
CVSS
8.8
EPSS (exploit probability)
1.5%
Status
patched
Published