Search
Find merged stories by title or summary.
SolarWinds Observability Flaws Let Unauthenticated Attackers Execute Remote Code
SolarWinds released Observability Self-Hosted 2026. 2. 3 to address two critical remote code execution vulnerabilities that could let unauthenticated attackers compromise affected deployments. The flaws, tracked as CVE-2026-28324 and CVE-2026-28325, carry CVSS severity scores of 9. 8 and 8. 8, respectively, and security researcher Kai Huang of Armadin reported them. SolarWinds said both vulnerabilities affect deployments operating under specific non-default communication or configuration conditions, making configuration reviews as important as applying the available update. SolarWinds Observability Flaws CVE-2026-28324 is a critical remote code execution vulnerability with a CVSS score of 9. 8. According to SolarWinds, the issue stems from insufficient integrity checks in SolarWinds Observability Self-Hosted.
Critical SolarWinds Flaws Let Attackers Remotely Execute Code on Observability Servers
SolarWinds released Observability Self-Hosted 2026. 2. 3 to fix two serious vulnerabilities that could let unauthenticated attackers remotely execute code on affected observability servers . The flaws, tracked as CVE-2026-28324 and CVE-2026-28325, affect specific non-default configurations and communication modes. The update was released on September 22, 2026, and is especially important for organizations running SolarWinds Observability Self-Hosted in environments with Web Performance Monitor, or WPM, players. Successful exploitation could let a remote attacker run arbitrary commands on a vulnerable server without logging in first. CVE-2026-28324 is rated 9. 8 out of 10 on the CVSS severity scale, making it a critical issue.
You've reached the end of current stories for this search.
