SolarWinds Patches Two Routes Into Its Monitoring Servers
A monitoring server sees deep into an organisation. It may reach network devices, cloud platforms, credentials and operational data. That makes two newly patched unauthenticated remote-code paths important even though neither affects every default installation.
SolarWinds fixed both issues in Observability Self-Hosted 2026.2.3. The vendor says versions 2026.2.2 and earlier are affected when the relevant configuration condition is present.
One flaw depends on a non-secure configuration
CVE-2026-28324 is rated critical at 9.8. SolarWinds says insufficient integrity checks can lead to unauthenticated remote code execution on installations using a non-default and non-secure configuration.
The published vector is network-reachable, low complexity, requires no privileges and no user interaction, with high confidentiality, integrity and availability impact. The configuration qualifier must remain part of the risk statement. It is not evidence that a standard deployment is exposed by default.
The second flaw requires a specific communication mode
CVE-2026-28325 is rated high at 8.8. Its advisory describes deserialisation of untrusted data when the application uses a specific communication mode.
Its vector is adjacent rather than fully network-wide, but it still requires no authentication or user action and carries high impact across confidentiality, integrity and availability.
SolarWinds has not reported exploitation of either issue. The reviewed sources did not identify a public proof of concept or general workaround. The fixed release is the reliable remediation path.
Configuration discovery is part of patching
Teams should not read “non-default” as “not us”. Monitoring platforms accumulate installation history, inherited settings, migration exceptions and communication choices that current owners may not remember. A configuration-specific vulnerability can expose exactly the older or more customised deployments that are hardest to upgrade quickly.
- Inventory every Observability Self-Hosted deployment. Include primary, standby, laboratory and acquired environments.
- Upgrade to 2026.2.3 or later. Verify the installed and running version after maintenance.
- Identify the relevant settings. Ask SolarWinds to identify the triggering settings for your deployment where the public advisories do not name them clearly.
- Reduce reachability. Restrict management and service interfaces to the systems and administrators that need them. Do not expose monitoring control planes broadly.
- Preserve and review evidence. Investigate unexpected service execution, child processes, configuration changes, new accounts and outbound connections during the vulnerable period.
- Review connected credentials. A monitoring server compromise matters because of what the platform can reach. Scope credential rotation and downstream investigation to actual evidence and stored integrations.
BlackTree recently covered a separate SolarWinds Access Rights Manager issue involving a static key. The new Observability flaws affect a different product and trust boundary, so they deserve separate inventory and remediation checks rather than being treated as an update to the ARM article.
Sources
- SolarWinds advisory for the insufficient-integrity-check issue, first published 22 September 2026. The page provides no publication time.
- SolarWinds advisory for the deserialisation issue, first published 22 September 2026. The page provides no publication time.
- SolarWinds Platform 2026.2.3 release notes, release dated 22 September 2026. The page provides no publication time.
- SecurityWeek, independent reporting, published 24 September 2026 at 06:40 ET.


