SolarWinds released security advisories for two vulnerabilities affecting SolarWinds Observability Self-Hosted 2026.2.2 products. The first vulnerability, CVE-2026-28324 (Critical – CVSS v3.1 9.8), is an unauthenticated remote code execution vulnerability due to insufficient integrity checks, affecting installations configured in a non-default and non-secure configuration. The second vulnerability, CVE-2026-28325 (High – CVSS v3.1 8.8), is an unauthenticated remote code execution vulnerability stemming from deserialization of untrusted data when the application is configured to use a specific communication mode. SolarWinds recommends upgrading to version 2026.2.3 immediately after appropriate testing.
VulnerabilitySecurity
SolarWinds Observability Self-Hosted Vulnerabilities

