CVE-2026-28325

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability stemming from deserialization of untrusted data when the application is configured to use a specific communication mode.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 7 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked 1d ago at 6 mentions (2026-09-23); latest day: 1
  • 7 total mentions across 2 days

Deep dive

Activity timeline7 mentions / 2d
02356Mentions · 2026-09-23: 6Mentions · 2026-09-24: 109-2309-24
Referenced assets3 URLs
Full discourse7 posts
  • Armadin@ArmadinSecurity

    The ARM chain was not the only finding our team turned up this cycle. Two more CVEs landed in SolarWinds Observability Self-Hosted, CVE-2026-28324 and CVE-2026-28325. Both unauthenticated RCE, both fixed in 2026.2.3. All three were discovered by our senior capability researcher, @mhskai2017. Note that all three RCEs affect ALL versions. We'll provide details on these in two weeks.

    21032242.4K
    553 followersView on X
  • Dark Web Intelligence@DailyDarkWeb

    🚨 SOLARWINDS PATCHES TWO UNAUTHENTICATED RCE FLAWS IN OBSERVABILITY SELF-HOSTED — ONE RATED CVSS 9.8 SolarWinds has released Observability Self-Hosted 2026.2.3 to fix two newly disclosed remote-code-execution vulnerabilities that require no authentication. • CVE-2026-28324 — CVSS 9.8 Critical — unauthenticated RCE caused by insufficient integrity checks • CVE-2026-28325 — CVSS 8.8 High — unauthenticated RCE involving deserialization of untrusted data • CVE-2026-28324 affects deployments using a non-default, non-secure configuration • CVE-2026-28325 requires a specific communication mode • Both flaws affect versions prior to 2026.2.3 and were reported by Kai Huang of Armadin • Successful exploitation can allow arbitrary code execution on the underlying SolarWinds server without credentials • SolarWinds released the fixes in version 2026.2.3 on September 22 • No confirmed in-the-wild exploitation or public PoC has been identified at this time ⚠️ Analyst Note: The configuration prerequisites limit the exposed population, but the target is high-value. Observability servers often have broad visibility into enterprise infrastructure and can hold credentials, topology information and privileged integrations useful for lateral movement. Organizations running SolarWinds Observability Self-Hosted should verify both the software version and whether either vulnerable non-default communication/configuration mode is enabled. Original SolarWinds release notes: https://documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/solarwinds_platform_2026-2-3_release_notes.htm #SolarWinds #CVE202628324 #CVE202628325 #RCE #Vulnerability #NetworkSecurity #ThreatIntel #DDW

    1522266.2K
    204.9K followersView on X
  • Omega DST@Omega_Dst

    🚨 Atención: Vulnerabilidad crítica en SolarWinds SolarWinds lanzó la v.2026.2.3 para parchear 2 fallos de RCE sin autenticación en Observability Self-Hosted: 🔴 CVE-2026-28324 (CVSS 9.8) 🟠 CVE-2026-28325 (CVSS 8.8) Permiten ejecutar código sin credenciales. Actualiza ya!!

    00110231
    769 followersView on X
  • Shah Sheikh@shah_sheikh

    SolarWinds Patches Critical RCE Flaws in Observability Self-Hosted: The vulnerabilities, tracked as CVE-2026-28324 and CVE-2026-28325, can be exploited without authentication. The post SolarWinds Patches Critical RCE Flaws in Observability Self-Hosted… https://www.securityweek.com/solarwinds-patches-critical-rce-flaws-in-observability-self-hosted/?utm_source=dlvr.it&utm_medium=twitter https://t.co/MqtlHqZR56

    0000019
    2.3K followersView on X
  • Christopher Elliott@Chris_L_Elliott

    SolarWinds Observability Self-Hosted 2026.2.3 fixes two unauth RCEs: CVE-2026-28324 (CVSS 9.8, integrity checks on non-default/non-secure installs) and CVE-2026-28325 (8.8, deserialization on a specific WPM/comms mode). "Non-default" is not a free pass — inventory every main polling engine + remote WPM player, then prove the build is 2026.2.3. Passive→active flip and auto-passwords on remotes are part of the fix. 2024.2 and older are past EoE.

    0000034
    60 followersView on X
  • Christopher Elliott@Chris_L_Elliott

    @DailyDarkWeb Self-hosted Observability is the nasty one here — CVSS 9.8 unauth RCE (CVE-2026-28324) plus the 8.8 deser path (CVE-2026-28325). If you can’t hit 2026.2.3 today, lock down WPM agent-to-server (player password / network restrict) before you call residual risk closed.

    0000037
    60 followersView on X
  • Armadin@ArmadinSecurity

    View the CVE-2026-28325 listing: https://www.solarwinds.com/trust-center/security-advisories/cve-2026-28325

    00000117
    553 followersView on X

Explore more