
The ARM chain was not the only finding our team turned up this cycle. Two more CVEs landed in SolarWinds Observability Self-Hosted, CVE-2026-28324 and CVE-2026-28325. Both unauthenticated RCE, both fixed in 2026.2.3. All three were discovered by our senior capability researcher, @mhskai2017. Note that all three RCEs affect ALL versions. We'll provide details on these in two weeks.




