securityonline.info 23 Sept 2026, 01:00 UTC

SolarWinds Fixes Critical Flaws Enabling Remote Code Execution

SolarWinds Fixes Critical Flaws Enabling Remote Code Execution
CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

ON 22 September 2026, SolarWinds released updates for two critical vulnerabilities in SolarWinds Observability Self-Hosted. CVE-2026-28324, rated 9.8 on the CVSS scale, involves insufficient integrity checks in non-default configurations. CVE-2026-28325, rated 8.8, concerns insecure deserialisation of untrusted data when particular communication modes are enabled.

According to the report, unauthenticated attackers could send malformed requests or crafted serialised objects over the network and achieve arbitrary code execution under specific conditions, potentially compromising the underlying monitoring server.

The affected products are SolarWinds Observability Self-Hosted installations running versions earlier than 2026.2.3. Systems using non-secure communication settings or custom Web Performance Monitoring configurations face the greatest stated risk. The article says the flaws were responsibly disclosed and that neither exploitation in the wild nor publicly available proof-of-concept code had been confirmed. SolarWinds administrators should upgrade to version 2026.2.3, following the vendor’s release notes.

The release also changes passive WPM players to secure active communication modes; administrators are additionally advised to review network configurations and isolate monitoring servers where possible.

View full article

Article by CyberSIXT