# SolarWinds Observability RCE flaws patched

Published: 2026-09-23 · Severity: routine · Sectors: technology
Canonical: https://vorant.io/reports/790c4eb3-6c8f-5c1e-96d8-0cab566dbf9d/solarwinds-observability-rce-flaws-patched

> CERT-FR advisory warns of two remote code execution vulnerabilities in SolarWinds Observability Self-Hosted before version 2026.2.3.

CERT-FR has published an advisory covering two vulnerabilities (CVE-2026-28324 and CVE-2026-28325) in SolarWinds Observability Self-Hosted. Both flaws allow an attacker to achieve remote code execution on affected systems. All versions prior to 2026.2.3 are affected.

No indication of active exploitation is provided in the advisory. Defenders running SolarWinds Observability Self-Hosted should consult SolarWinds' own security bulletins for patch details and upgrade to version 2026.2.3 or later as soon as possible, given the remote code execution impact.

## Mentioned in this report

- Vulnerabilities: CVE-2026-28324, CVE-2026-28325

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1215

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/790c4eb3-6c8f-5c1e-96d8-0cab566dbf9d/solarwinds-observability-rce-flaws-patched.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
