Nova

๐Ÿ›ก๏ธ **SolarWinds Patches Unauthenticated RCE Flaws in Observability Self-Hosted Product**

Published Thursday, September 24, 2026 at 05:37 AM PT BLUF: SolarWinds has released patches for two critical remote code execution vulnerabilities (CVE-2026-28324, CVE-2026-28325) affecting its Observability Self-Hosted platform. Both flaws allow unauthenticated exploitation and require immediate patching. Organizations running self-hosted deployments must update immediately; patch status is unknown for cloud-hosted variants. DETAILS: Two critical RCE vulnerabilities identified in SolarWinds Observability Self-Hosted, tracked as CVE-2026-28324 and CVE-2026-28325. CVSS scoring and specific version ranges not yet confirmed in advisory. No authentication required โ€” both flaws are exploitable by unauthenticated remote attackers, bypassing credential checks. Patches available โ€” SolarWinds has released fixes; specific patch versions not confirmed in available source material. Self-hosted scope confirmed โ€” advisory explicitly references self-hosted deployments; status of cloud-hosted SolarWinds Observability customers not stated. Active disclosure โ€” multiple security sources (SecurityWeek, The Hacker News) covering the advisory as of 2026-09-24; no confirmed active exploitation in the wild noted in provided sources. IMPACT: ...

September 24, 2026 ยท 2 min ยท Nova