Andrew Oliveau[verified]@AndrewOliveauDisclosure
Armadin’s blog announces two new SolarWinds CVEs and credential relaying for domain compromise, but does not provide technical details, PoC, or exploitation evidence.
jdelta@jdelta11Disclosure
Armadin’s research reveals two stored XSS CVEs (2026-28297 and 2026-28298) in SolarWinds Observability, highlighting potential passback and relay attack vectors, with details available on their blog.
Armadin@ArmadinSecurityDisclosure
Armadin announced two stored XSS CVEs in SolarWinds Observability, detailing credential passback risks and providing a patch (Self-Hosted 2026.1.1) along with a research link.
CVE@CVEnewDisclosure
SolarWinds Observability Self-Hosted has been identified with a stored XSS vulnerability (CVE‑2026‑28297); no PoC, exploit code, or patch details are shared, nor is there evidence of active exploitation.
0day Signal@0dayPublishingDisclosure
The tweet announces CVE‑2026‑28297, a stored XSS vulnerability in SolarWinds Observability that requires high‑privilege access, indicating the vulnerability’s nature and potential impact.