SolarWinds has released SolarWinds Observability Self-Hosted version 2026.2.3 to address two critical remote code execution (RCE) vulnerabilities.
These vulnerabilities could allow unauthenticated attackers to compromise exposed deployments under specific configurations. The vulnerabilities are tracked as CVE-2026-28324 and CVE-2026-28325, with CVSS severity scores of 9.8 and 8.8, respectively.
This update was released on September 22, 2026, and focuses primarily on security remediation and operational fixes, with no new product features included. Organizations using affected deployments should consider this update a high-priority patching event.
CVE-2026-28324 is an unauthenticated remote code execution vulnerability caused by insufficient integrity checks.
SolarWinds stated that this issue affects installations configured in a “non-default and non-secure configuration,” meaning exposure depends on how the affected instance has been deployed and secured. This vulnerability received a near-maximum CVSS score of 9.8.
The second vulnerability, CVE-2026-28325, is also an unauthenticated RCE issue related to deserializing untrusted data. According to SolarWinds, exploitation of this flaw requires the application to be configured with a specific communication mode. It carries a CVSS score of 8.8.
Kai Huang of Armadin reported both vulnerabilities through responsible disclosure. SolarWinds has not provided technical exploit details, affected endpoint information, or evidence of active exploitation in the release notes.
Unauthenticated RCE vulnerabilities are considered among the highest-risk software weaknesses because attackers may exploit them without needing valid credentials to execute code on a vulnerable server.
If an affected SolarWinds instance is internet-facing or reachable from a compromised internal network segment, successful exploitation could provide an initial foothold for lateral movement, credential theft, service disruption, or ransomware deployment.
The actual attack surface is dependent on the configuration. Organizations should not assume a system is safe solely because it uses a default deployment.
Security teams must verify communication-mode settings, review externally exposed SolarWinds services, and assess whether past customizations introduced the insecure configurations mentioned in the advisory.
SolarWinds recommends that organizations upgrade existing deployments via the SolarWinds Platform interface by navigating to Settings > My Deployment.
This installer will upgrade the deployment, including SolarWinds Platform products and scalability engines. Administrators who are skipping multiple versions should review the vendor’s release notes aggregator and supported upgrade paths before proceeding.
Until all systems are upgraded, defenders should take the following steps:
The update also modifies certain WPM player behaviors. After the upgrade, passive players installed on the main polling engine will switch to active, player-initiated communication, while remotely installed passive players will receive randomly generated strong passwords during automatic upgrade workflows.
Organizations running older versions should act quickly, especially if systems are externally reachable or operate with legacy communication configurations.
Patching, combined with exposure reduction and configuration reviews, is the most immediate defense against these unauthenticated RCE vulnerabilities.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
San Francisco, USA, September 25th, 2026, CyberNewswire Archipelo today announced Salmon, Execution Verification Infrastructure (EVI)…
A vulnerability in the Linux kernel’s AF_ALG cryptographic interface, which has existed for 14 years,…
ServiceNow has disclosed five vulnerabilities affecting its AI Platform, including two critical flaws that could…
Research from Transluce shows that autonomous AI agents shifted from standard web data collection to…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability affecting WSO2,…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical vulnerabilities affecting multiple…