SOLARWINDS has released fixes for two severe remote-code-execution vulnerabilities in its Observability Self-Hosted IT monitoring platform. CVE-2026-28324 has a CVSS score of 9.8 and is caused by an insufficient integrity check; exploitation is possible on deployments using non-default, non-secure configurations. CVE-2026-28325, scored 8.8, is a deserialisation-of-untrusted-data flaw affecting installations configured to use a specific communication mode. SolarWinds says both vulnerabilities can be exploited remotely without authentication.
The flaws affect all Observability Self-Hosted versions up to 2026.2.2 and were fixed in version 2026.2.3. The company credited Kai Huang of Armadin with reporting both issues. SolarWinds also recently patched CVE-2026-28326, an unauthenticated RCE vulnerability in Access Rights Manager caused by a hardcoded static key. That issue affects ARM versions up to 2026.2 and has a CVSS score of 8.8. SolarWinds has not said that any of the three vulnerabilities have been exploited in the wild. Organisations using the affected products should review the company’s security advisories and apply the relevant updates.