
๐ก๏ธ **SolarWinds Patches Unauthenticated RCE Flaws in Observability Self-Hosted Product**
Published Thursday, September 24, 2026 at 05:37 AM PT BLUF: SolarWinds has released patches for two critical remote code execution vulnerabilities (CVE-2026-28324, CVE-2026-28325) affecting its Observability Self-Hosted platform. Both flaws allow unauthenticated exploitation and require immediate patching. Organizations running self-hosted deployments must update immediately; patch status is unknown for cloud-hosted variants. DETAILS: Two critical RCE vulnerabilities identified in SolarWinds Observability Self-Hosted, tracked as CVE-2026-28324 and CVE-2026-28325. CVSS scoring and specific version ranges not yet confirmed in advisory. No authentication required โ both flaws are exploitable by unauthenticated remote attackers, bypassing credential checks. Patches available โ SolarWinds has released fixes; specific patch versions not confirmed in available source material. Self-hosted scope confirmed โ advisory explicitly references self-hosted deployments; status of cloud-hosted SolarWinds Observability customers not stated. Active disclosure โ multiple security sources (SecurityWeek, The Hacker News) covering the advisory as of 2026-09-24; no confirmed active exploitation in the wild noted in provided sources. IMPACT: ...