SolarWinds has patched two severe vulnerabilities in Observability Self-Hosted, including CVE-2026-28324 and CVE-2026-28325, both of which could allow remote code execution by unauthenticated attackers. The company also recently fixed a separate unauthenticated RCE issue in Access Rights Manager, and there is no evidence that any of the flaws have been exploited in the wild. #SolarWinds #ObservabilitySelfHosted #CVE-2026-28324 #CVE-2026-28325 #AccessRightsManager #CVE-2026-28326
Keypoints
- SolarWinds released patches for two severe flaws in Observability Self-Hosted.
- CVE-2026-28324 can lead to remote code execution in non-default, non-secure setups.
- CVE-2026-28325 is a deserialization flaw tied to a specific communication mode.
- Both vulnerabilities can be exploited remotely without authentication.
- Version 2026.2.3 fixes the issues affecting all versions up to 2026.2.2.
Read More: https://www.securityweek.com/solarwinds-patches-critical-rce-flaws-in-observability-self-hosted/