SolarWinds Patches Two Critical RCE Flaws in Observability Self-Hosted
SolarWinds released fixes for two remote code execution vulnerabilities in Observability Self-Hosted: CVE-2026-28324 (CVSS 9.8) and CVE-2026-28325 (CVSS 8.8). Both are exploitable by unauthenticated remote attackers and affect versions up to 2026.2.2, patched in 2026.2.3.
- CVE-2026-28324: CVSS 9.8, insufficient integrity check leads to RCE
- CVE-2026-28325: CVSS 8.8, deserialization of untrusted data
- Versions up to 2026.2.2 affected, fixed in 2026.2.3
- Both flaws reported by Kai Huang of Armadin, no known exploitation
Read next
Security