Andrew Oliveau[verified]@AndrewOliveauDisclosure
Armadin’s brief post introduces two new SolarWinds CVEs—CVE‑2026‑28297 and CVE‑2026‑28298—and credential relaying, but it does not detail the vulnerability type, PoC, or exploitation activity.
jdelta@jdelta11Disclosure
The tweet announces the discovery of two stored XSS vulnerabilities (CVE-2026-28297 and CVE-2026-28298) in SolarWinds Observability, references a detailed blog post, but does not mention patches, active exploitation, or a false positive.
Armadin@ArmadinSecurityDisclosure
Armadin disclosed two stored‑XSS vulnerabilities in SolarWinds Observability (CVE‑2026‑28297/28298), highlighting credential passback attacks that could lead to full domain compromise, and noted the issue is fixed in the 2026.1.1 self‑hosted release.
CVE@CVEnewDisclosure
The post announces a stored XSS flaw (CVE‑2026‑28298) in SolarWinds Observability Self‑Hosted that may allow unintended script execution, but offers no PoC, exploit, or mitigation details.
0day Signal@0dayPublishingDisclosure
SolarWinds Observability CVE‑2026‑28298 is a stored XSS issue that could enable persistence; the post announces the vulnerability and notes the technical flaw but offers no PoC, exploit, or patch details.