SolarWinds patches critical RCE flaws in Observability Self-Hosted

Summary

SolarWinds has released critical patches for two vulnerabilities in its Observability Self-Hosted monitoring solution that could allow remote code execution (RCE), impacting all versions up to 2026.2.2. The first flaw, CVE-2026-28324, scores 9.8 on the CVSS scale and arises from insufficient integrity checks, while the second, CVE-2026-28325, scores 8.8 due to a deserialization issue. Both vulnerabilities can be exploited remotely without authentication. SolarWinds noted that these flaws were responsibly disclosed by a security researcher, and there have been no reports of them being exploited in the wild. This patching effort follows several recent updates aimed at addressing similar RCE vulnerabilities across the company's products.

Analysis

Kai Huang: Kai Huang is a security researcher at Armadin who reported the two critical vulnerabilities in SolarWinds Observability Self-Hosted. His findings prompted the company to issue patches for the remote code execution flaws. SolarWinds: SolarWinds develops IT infrastructure management and monitoring software solutions for enterprises. The company has released patches addressing two critical remote code execution vulnerabilities in its Observability Self-Hosted product that affect versions prior to 2026.2.3. It also patched a separate unauthenticated RCE issue in Access Rights Manager the prior week. Security Patching: SolarWinds has addressed multiple remote code execution vulnerabilities across its product line in recent weeks. Vulnerability Disclosure: The flaws were responsibly disclosed by a security researcher with no reports of active exploitation.

Categories

tech
View Original Tweet