# SolarWinds Observability RCE flaws patched

Published: 2026-09-23 · Severity: routine · Sectors: technology
Canonical: https://vorant.io/reports/4e0cd2e3-b515-5dba-afaa-72abbaea065e/solarwinds-observability-rce-flaws-patched

> SolarWinds patched two unauthenticated RCE vulnerabilities in Observability Self-Hosted, one via unsafe deserialization, CVSS up to 9.8.

NCSC-NL published an advisory covering two vulnerabilities in SolarWinds Observability Self-Hosted that allow unauthenticated remote code execution. CVE-2026-28324 (CVSS 9.8) stems from deserialization of untrusted data when a specific communication mode is in use. CVE-2026-28325 (CVSS 8.8) results from insufficient integrity checks, primarily affecting installations that deviate from default configurations and use insecure settings.

Both issues allow an attacker to execute arbitrary code remotely without authentication, making them serious risks for exposed instances. SolarWinds has released updates addressing both vulnerabilities. No in-the-wild exploitation is mentioned in the advisory. Defenders running SolarWinds Observability Self-Hosted should apply the vendor updates promptly, review configuration against SolarWinds' hardening guidance, and ensure any non-default or insecure communication settings are remediated.

## Mentioned in this report

- Vulnerabilities: CVE-2026-28324, CVE-2026-28325

Source reporting: https://advisories.ncsc.nl/2026/ncsc-2026-0388.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/4e0cd2e3-b515-5dba-afaa-72abbaea065e/solarwinds-observability-rce-flaws-patched.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
