Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Ryuk Ransomware Operator Sentenced for Deploying Malware and Extortion
September 23, 2026
Critical AWS Lambda Flaw Bypasses IAM, Exposes Cloud Services
September 23, 2026
Critical Next.js CVE-2024-XXXXX RCE Flaw Lets Attackers Use SVG Files
September 23, 2026
Home/CyberSecurity News/Critical SolarWinds Observability RCE Flaws Patched
CyberSecurity News

Critical SolarWinds Observability RCE Flaws Patched

Key Takeaways SolarWinds has issued a critical patch for its Observability Self-Hosted platform. Two severe remote code execution (RCE) vulnerabilities, CVE-2026-28324 and CVE-2026-28325, have been...

Jennifer sherman
Jennifer sherman
September 23, 2026 3 Min Read
5 0

Key Takeaways

  • SolarWinds has issued a critical patch for its Observability Self-Hosted platform.
  • Two severe remote code execution (RCE) vulnerabilities, CVE-2026-28324 and CVE-2026-28325, have been addressed.
  • These flaws could allow unauthenticated attackers to execute arbitrary code on affected servers.
  • The vulnerabilities primarily impact specific non-default configurations and installations utilizing Web Performance Monitor (WPM) players.
  • Organizations should immediately update to Observability Self-Hosted version 2026.2.3.

Critical RCE Flaws Patched in SolarWinds Observability Self-Hosted

SolarWinds has released an urgent security update, Observability Self-Hosted version 2026.2.3, to mitigate two critical vulnerabilities that could enable unauthenticated remote code execution (RCE) on susceptible servers. These flaws, identified as CVE-2026-28324 and CVE-2026-28325, pose a significant risk, particularly to deployments configured in non-default modes or those integrating Web Performance Monitor (WPM) players.

Table Of Content

  • Key Takeaways
  • Critical RCE Flaws Patched in SolarWinds Observability Self-Hosted
  • Deep Dive into the Vulnerabilities
  • Post-Upgrade Considerations for WPM Deployments
  • What You Should Do

The patch, rolled out on September 22, 2026, is crucial for organizations utilizing SolarWinds Observability Self-Hosted, especially those with WPM players in their environment. Successful exploitation of these vulnerabilities could grant remote attackers the ability to execute arbitrary commands on a server without prior authentication.

Deep Dive into the Vulnerabilities

CVE-2026-28324, the more severe of the two, carries a CVSS score of 9.8 out of 10, categorizing it as a critical issue. SolarWinds indicated that this vulnerability stems from inadequate integrity checks within Observability Self-Hosted installations that are configured in a non-default, less secure manner.

While SolarWinds has not publicly disclosed proof-of-concept details, the high CVSS score underscores the urgency for defenders to prioritize patching for any exposed and specifically configured servers. The second vulnerability, CVE-2026-28325, is also an unauthenticated RCE issue, rated with a CVSS score of 8.8.

According to SolarWinds, CVE-2026-28325 arises from unsafe deserialization of untrusted data when the application operates in a particular communication mode. Unsafe deserialization vulnerabilities occur when an application processes serialized data provided by an attacker without adequate validation, potentially leading to the execution of malicious objects or commands within the application’s context.

Both vulnerabilities were responsibly reported by Kai Huang of Armadin. SolarWinds confirms that these issues are resolved in version 2026.2.3, which focuses on security fixes and platform reliability enhancements rather than new features.

Post-Upgrade Considerations for WPM Deployments

The update also introduces changes to the behavior of certain WPM player deployments. Specifically, passive WPM players that are installed by default on the main polling engine will transition from server-initiated to player-initiated communication post-upgrade.

Remote passive WPM players will automatically receive randomly generated strong passwords during their upgrade process. However, SolarWinds noted that players with the “Enable Upgrade” option disabled will not be automatically updated and require manual intervention from administrators. Active, player-initiated WPM players do not require a password following the upgrade.

What You Should Do

  • Immediate Patching: Administrators must upgrade their entire SolarWinds deployment to Observability Self-Hosted version 2026.2.3 without delay. This can be done via Settings > My Deployment, which updates both SolarWinds Platform products and associated scalability engines.
  • Inventory and Assessment: Before applying the update, security teams should identify all main polling engines, remote WPM players, and the communication modes currently in use within their environment.
  • Credential Review: Verify that all passive remote WPM players have strong, unique credentials, especially those that might not be automatically upgraded.
  • Manual Updates: Ensure that any systems excluded from automatic upgrades are updated manually.
  • Exposure Review: Assess server exposure and restrict management access to trusted networks only.
  • Logging and Monitoring: Continuously monitor SolarWinds application and Windows logs for any unexpected process execution or abnormal activity involving polling engines or WPM players.
  • End-of-Life Systems: Pay particular attention to older deployments. SolarWinds has ceased engineering support for Observability Self-Hosted 2024.2 and earlier versions, meaning these will no longer receive regular fixes or service releases and should be upgraded or decommissioned.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityVulnerability

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

ChatGPT macOS Feature Exposes User Data to Infostealers

Next Post

Fake Streaming App Exposes Android Phones to Remote Takeover

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
NVIDIA Patches High-Severity Linux Driver Flaws Exposing Sensitive Data
September 23, 2026
Autonomous AI Fraud and Digital Trust Abuse Mark New Phase in Cyberattacks
September 23, 2026
Critical Vulnerability in Terraform Providers Exposed by Developer Tools Malware
September 23, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us