SolarWinds Observability Self-Hosted CVE-2026-28325 (CVSS 8.8): unauth RCE via deserialization — fix 2026.2.3
SolarWinds Trust Center advisory CVE-2026-28325 documents an unauthenticated remote code execution vulnerability in Observability Self-Hosted stemming from deserialization of untrusted data when the application is configured to use a specific communication mode. CVSS 3.1 8.8 HIGH (AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H — adjacent network). Affected: Observability Self-Hosted 2026.2.2 and below. Fixed: 2026.2.3. Credit: Kai Huang (Armadin). No in-the-wild exploitation stated by vendor. Sibling CVE-2026-28324 (CVSS 9.8 integrity-check RCE) is a separate desk card on the same fix train. Primary: SolarWinds Trust Center; wire: SecurityWeek 24 Sep 2026.
- Product
- SolarWinds Observability Self-Hosted
- Versions
- Affected: 2026.2.2 and below (specific communication mode); Fixed: 2026.2.3
- CVSS
- (CVSS 3.1 HIGH, vendor)
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - Exploited in Australia?
- unknown
- Patch to
- Upgrade Observability Self-Hosted to 2026.2.3; review communication-mode configuration; restrict adjacent-network access to Observability services until patched
Primary: SolarWinds Trust Center — CVE-2026-28325 Observability Self-Hosted · Vendor: SolarWinds — Observability Self-Hosted CVE-2026-28325 · CVE: CVE-2026-28325, CVE-2026-28324 · SecurityWeek — SolarWinds Observability Self-Hosted RCE patches (24 Sep 2026)
