SolarWinds has released a security update for its on-premises Observability Self-Hosted platform, addressing two significant remote code execution (RCE) vulnerabilities. The more severe flaw, CVE-2026-28324, is rated critical with a CVSS score of 9.8 and can be exploited by an unauthenticated attacker in certain non-default configurations. A second high-severity flaw, CVE-2026-28325 (CVSS 8.8), involves the deserialization of untrusted data.
Successful exploitation of either vulnerability could allow an attacker to gain a foothold within a network, a serious risk given the privileged access that observability platforms typically possess. SolarWinds has released version 2026.2.3 to fix the issues and strongly advises all customers using the self-hosted product to update immediately. There is currently no evidence of active exploitation.
Two distinct vulnerabilities were addressed in this update:
CVE-2026-28324 (CVSS 9.8, Critical): This is an insufficient integrity check vulnerability. It allows a remote, unauthenticated attacker to achieve RCE on deployments that are using a "non-default and non-secure configuration." While the specific configuration was not detailed, the high CVSS score suggests the prerequisite is not uncommon or difficult to achieve.
CVE-2026-28325 (CVSS 8.8, High): This vulnerability is caused by the deserialization of untrusted data (T1574 - Hijack Execution Flow). An unauthenticated attacker can exploit this flaw to achieve RCE when the application is configured to use a specific, non-default communication mode.
Both vulnerabilities were responsibly disclosed by security researcher Kai Huang of Armadin. The lack of an authentication requirement for exploitation makes these flaws particularly dangerous.
Only the self-hosted, on-premises version of the SolarWinds Observability platform is affected. The SaaS version is not impacted.
As of the disclosure, SolarWinds has stated there is no indication that these vulnerabilities have been exploited in the wild. However, given the history of attacks against SolarWinds products and the severity of these flaws, it is highly likely that threat actors will develop exploits and begin scanning for vulnerable systems in the near future.
Observability and monitoring platforms are high-value targets for attackers. By design, they have privileged access and credentials to connect to a wide array of servers, applications, databases, and network devices across an organization. A successful RCE exploit on the SolarWinds Observability platform could provide an attacker with:
T1562 - Impair Defenses).Security teams can hunt for signs of exploitation attempts or compromise:
log_sourceSolarWinds Observability Platform Logsnetwork_traffic_patternprocess_nameSolarWinds.Administration.exe (or related services)D3-NTA: Network Traffic Analysis.The primary and most effective mitigation is to upgrade SolarWinds Observability Self-Hosted to the patched version 2026.2.3.
Mapped D3FEND Techniques:
Restrict network access to the SolarWinds platform to only trusted administrative subnets to reduce the attack surface.
Mapped D3FEND Techniques:
Review and apply SolarWinds' security hardening guides to avoid using insecure, non-default configurations.
Mapped D3FEND Techniques:
The immediate and most critical action is to patch all instances of SolarWinds Observability Self-Hosted to version 2026.2.3. Due to the critical, unauthenticated nature of CVE-2026-28324, this should be treated as an emergency patch. Prioritize internet-facing instances first, followed by internal ones. Before deploying the update, take a snapshot or backup of the server and its configuration to ensure a rollback path. After the update, verify that the platform is running the new version and that all monitoring functions are operating as expected. Given the platform's privileged position in the network, delaying this patch exposes the entire monitored environment to potential compromise.
As both vulnerabilities are noted to be exploitable in 'non-default' configurations, a thorough configuration review is a crucial defense-in-depth measure. Audit your SolarWinds Observability platform against the vendor's official hardening guides. Pay special attention to settings related to communication modes and integrity checks. Revert any 'non-secure' custom configurations back to the secure default unless there is a compelling, documented business reason. This action directly mitigates the risk described in the advisories and reduces the overall attack surface of the platform, potentially protecting against future, unknown vulnerabilities.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.