SolarWinds released SolarWinds Observability Self-Hosted 2026.2.3 to remediate two unauthenticated remote-code-execution flaws: CVE-2026-28324 (CVSS 9.8) and CVE-2026-28325 (CVSS 8.8). CVE-2026-28324 affects deployments using a non-default, non-secure configuration and stems from insufficient integrity checks (CWE-345); it can be exploited remotely without authentication or user interaction, with potential total compromise of confidentiality, integrity, and availability. CVE-2026-28325 arises from deserialization of untrusted data in a specific communication mode.
CISA SSVC data for CVE-2026-28324 identifies exploitation as automatable and the technical impact as total, although no known active exploitation was reported. Organizations running affected self-hosted SolarWinds environments should prioritize upgrading to version 2026.2.3, especially where non-default insecure configurations or the affected communication mode are in use. The update also changes Web Performance Monitor player upgrade behavior by migrating default passive players to active mode and generating strong passwords for remotely installed passive players, alongside platform and application-monitoring defect fixes.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
SolarWinds received CVE-2026-28325 for an unauthenticated RCE vulnerability caused by deserialization of untrusted data in a specific communication mode. CISA's SSVC assessment recorded no known exploitation, no automation, and total technical impact.
CVE-2026-28324 was added to the CVE record. The critical 9.8 vulnerability permits unauthenticated remote code execution in SolarWinds Observability Self-Hosted deployments using a non-default, non-secure configuration due to insufficient integrity checks.
SolarWinds released version 2026.2.3, fixing unauthenticated RCE flaws CVE-2026-28324 (CVSS 9.8) and CVE-2026-28325 (CVSS 8.8). Kai Huang of Armadin responsibly reported both vulnerabilities; CVE-2026-28325 involves deserialization of untrusted data in a specific communication mode.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourcedocumentation.solarwinds.com
Open sourcesolarwinds.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.