SolarWinds Fixes RCE Flaws (CVE-2026-28324, CVE-2026-28325)

SolarWinds Patches Critical Unauthenticated RCE Flaws in Observability Platform

CRITICAL
September 25, 2026
4m read
VulnerabilityPatch Management

Related Entities

Organizations

Products & Tech

SolarWinds Observability Self-Hosted

Other

Kai Huang

CVE Identifiers

CVE-2026-28324
CRITICAL
CVSS:9.8
CVE-2026-28325
HIGH
CVSS:8.8

Full Report

Executive Summary

SolarWinds has released a security update for its on-premises Observability Self-Hosted platform, addressing two significant remote code execution (RCE) vulnerabilities. The more severe flaw, CVE-2026-28324, is rated critical with a CVSS score of 9.8 and can be exploited by an unauthenticated attacker in certain non-default configurations. A second high-severity flaw, CVE-2026-28325 (CVSS 8.8), involves the deserialization of untrusted data.

Successful exploitation of either vulnerability could allow an attacker to gain a foothold within a network, a serious risk given the privileged access that observability platforms typically possess. SolarWinds has released version 2026.2.3 to fix the issues and strongly advises all customers using the self-hosted product to update immediately. There is currently no evidence of active exploitation.


Vulnerability Details

Two distinct vulnerabilities were addressed in this update:

  • CVE-2026-28324 (CVSS 9.8, Critical): This is an insufficient integrity check vulnerability. It allows a remote, unauthenticated attacker to achieve RCE on deployments that are using a "non-default and non-secure configuration." While the specific configuration was not detailed, the high CVSS score suggests the prerequisite is not uncommon or difficult to achieve.

  • CVE-2026-28325 (CVSS 8.8, High): This vulnerability is caused by the deserialization of untrusted data (T1574 - Hijack Execution Flow). An unauthenticated attacker can exploit this flaw to achieve RCE when the application is configured to use a specific, non-default communication mode.

Both vulnerabilities were responsibly disclosed by security researcher Kai Huang of Armadin. The lack of an authentication requirement for exploitation makes these flaws particularly dangerous.

Affected Systems

  • Product: SolarWinds Observability Self-Hosted
  • Affected Versions: All versions up to and including 2026.2.2
  • Patched Version: 2026.2.3

Only the self-hosted, on-premises version of the SolarWinds Observability platform is affected. The SaaS version is not impacted.

Exploitation Status

As of the disclosure, SolarWinds has stated there is no indication that these vulnerabilities have been exploited in the wild. However, given the history of attacks against SolarWinds products and the severity of these flaws, it is highly likely that threat actors will develop exploits and begin scanning for vulnerable systems in the near future.

Impact Assessment

Observability and monitoring platforms are high-value targets for attackers. By design, they have privileged access and credentials to connect to a wide array of servers, applications, databases, and network devices across an organization. A successful RCE exploit on the SolarWinds Observability platform could provide an attacker with:

  • An initial foothold deep within the network.
  • Access to the credentials and secrets used by the platform to monitor other systems.
  • A powerful pivot point for lateral movement and widespread compromise.
  • The ability to tamper with monitoring and alerting, effectively blinding the security team to further malicious activity (T1562 - Impair Defenses).

Cyber Observables — Hunting Hints

Security teams can hunt for signs of exploitation attempts or compromise:

Type
log_source
Value
SolarWinds Observability Platform Logs
Description
Look for unexpected error messages, process crashes, or anomalous log entries related to integrity checks or data deserialization.
Type
network_traffic_pattern
Value
Inbound connections with malformed data payloads.
Description
Exploitation would likely involve sending a crafted request to a specific API endpoint on the platform.
Type
process_name
Value
SolarWinds.Administration.exe (or related services)
Description
Monitor for unexpected child processes, outbound network connections, or crashes of the main platform services.

Detection Methods

  • Version Scanning: The most reliable detection method is to perform an inventory of all SolarWinds Observability Self-Hosted instances and verify they are running the patched version (2026.2.3) or later.
  • Log Analysis: Review application and system logs on the servers hosting the platform. Look for any evidence of suspicious activity, such as unexpected configuration changes or anomalous access patterns, particularly around the time of the vulnerability disclosure.
  • Network Monitoring: Monitor network traffic to and from the SolarWinds servers for any unusual connections or data transfers that could indicate a C2 channel. This aligns with D3FEND's D3-NTA: Network Traffic Analysis.

Remediation Steps

  1. Update Immediately: The only way to remediate these vulnerabilities is to upgrade all instances of SolarWinds Observability Self-Hosted to version 2026.2.3.
  2. Review Configuration: As a defense-in-depth measure, review the platform's configuration to ensure it is not using the "non-default and non-secure" settings mentioned in the advisory for CVE-2026-28324. Follow SolarWinds' hardening guides.
  3. Restrict Access: Ensure that access to the SolarWinds Observability platform's web interface and API endpoints is restricted to trusted internal IP addresses. While this may not block a determined attacker, it reduces the attack surface from opportunistic internet-wide scanning.

Timeline of Events

1
September 25, 2026
This article was published

MITRE ATT&CK Mitigations

The primary and most effective mitigation is to upgrade SolarWinds Observability Self-Hosted to the patched version 2026.2.3.

Mapped D3FEND Techniques:

Restrict network access to the SolarWinds platform to only trusted administrative subnets to reduce the attack surface.

Mapped D3FEND Techniques:

Review and apply SolarWinds' security hardening guides to avoid using insecure, non-default configurations.

Mapped D3FEND Techniques:

D3FEND Defensive Countermeasures

The immediate and most critical action is to patch all instances of SolarWinds Observability Self-Hosted to version 2026.2.3. Due to the critical, unauthenticated nature of CVE-2026-28324, this should be treated as an emergency patch. Prioritize internet-facing instances first, followed by internal ones. Before deploying the update, take a snapshot or backup of the server and its configuration to ensure a rollback path. After the update, verify that the platform is running the new version and that all monitoring functions are operating as expected. Given the platform's privileged position in the network, delaying this patch exposes the entire monitored environment to potential compromise.

As both vulnerabilities are noted to be exploitable in 'non-default' configurations, a thorough configuration review is a crucial defense-in-depth measure. Audit your SolarWinds Observability platform against the vendor's official hardening guides. Pay special attention to settings related to communication modes and integrity checks. Revert any 'non-secure' custom configurations back to the secure default unless there is a compelling, documented business reason. This action directly mitigates the risk described in the advisories and reduces the overall attack surface of the platform, potentially protecting against future, unknown vulnerabilities.

Sources & References

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

SolarWindsCVE-2026-28324CVE-2026-28325RCEvulnerabilitypatch managementobservability

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

⚡ Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.