Vulnerability
Published 2026-09-24
Verified 2026-09-27

SolarWinds Observability Self-Hosted CVE-2026-28325 (CVSS 8.8): unauth RCE via deserialization — fix 2026.2.3

SolarWinds Trust Center advisory CVE-2026-28325 documents an unauthenticated remote code execution vulnerability in Observability Self-Hosted stemming from deserialization of untrusted data when the application is configured to use a specific communication mode. CVSS 3.1 8.8 HIGH (AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H — adjacent network). Affected: Observability Self-Hosted 2026.2.2 and below. Fixed: 2026.2.3. Credit: Kai Huang (Armadin). No in-the-wild exploitation stated by vendor. Sibling CVE-2026-28324 (CVSS 9.8 integrity-check RCE) is a separate desk card on the same fix train. Primary: SolarWinds Trust Center; wire: SecurityWeek 24 Sep 2026.

Product
SolarWinds Observability Self-Hosted
Versions
Affected: 2026.2.2 and below (specific communication mode); Fixed: 2026.2.3
CVSS
(CVSS 3.1 HIGH, vendor)
Exploited in Australia?
unknown
Patch to
Upgrade Observability Self-Hosted to 2026.2.3; review communication-mode configuration; restrict adjacent-network access to Observability services until patched

Primary: SolarWinds Trust Center — CVE-2026-28325 Observability Self-Hosted · Vendor: SolarWinds — Observability Self-Hosted CVE-2026-28325 · CVE: CVE-2026-28325, CVE-2026-28324 · SecurityWeek — SolarWinds Observability Self-Hosted RCE patches (24 Sep 2026)

vulnerabilities cloud network