INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

SolarWinds Patches Multiple Critical RCE Flaws in Observability Software

| 2026-09-24 10:40 CRITICAL LOW EXPLOITED VULNERABILITY VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
On September 24, 2026, SolarWinds released patches for two severe vulnerabilities in Observability Self-Hosted that could be exploited for remote code execution (RCE). The first flaw, tracked as CVE-2026-28324 with a CVSS score of 9.8, is an insufficient integrity check issue leading to RCE on deployments that run non-default and non-secure configurations. Tracked as CVE-2026-28325 with a CVSS score of 8.8, the second bug is described as a deserialization of untrusted data weakness affecting installations configured to use a specific communication mode. The vulnerabilities impact all Observability Self-Hosted versions up to 2026.2.2 and were addressed in version 2026.2.3. SolarWinds credited Kai Huang from Armadin for reporting both flaws, which can be exploited by remote attackers without authentication.
Technical Mitigations AI-generated
• Patch SolarWinds Observability Self-Hosted to version 2026.2.3 for the insufficient integrity check issue (CVE-2026-28324) and deserialization of untrusted data weakness (CVE-2026-28325). • Update Access Rights Manager (ARM) to version 2026.2.1 to address the hard-coded static key vulnerability (CVE-2026-28326). • Apply a patch for Serv-U to resolve privilege escalation, remote code execution, and administrator account creation vulnerabilities (CVE-2026-28302 through CVE-2026-28317, CVE-2026-28321, CVE-2026-28323).
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-28304CVE-2026-28304 CVE-2026-28321CVE-2026-28321 CVE-2026-28326CVE-2026-28326 CVE-2026-28324CVE-2026-28324 CVE-2026-28323CVE-2026-28323 CVE-2026-28299CVE-2026-28299 CVE-2026-28317CVE-2026-28317 CVE-2026-28302CVE-2026-28302 CVE-2026-28325CVE-2026-28325
Target & Sectors
Global Scope
Incident Timeline
‎2026.2.1
The critical Remote Code Execution (RCE) flaws in SolarWinds Observability Self-Hosted have been resolved in version WHD 2026.2.1.
‎2026.2.2
Threat actors exploited critical Remote Code Execution (RCE) flaws in Observability Self-Hosted versions up to 2026.2.2 before the patch was released in version 2026.2.3.
infrastructure 2026.2.2
infrastructure 2026.2.3
‎2026/09/17
The company patched another unauthenticated Remote Code Execution (RCE) bug reported by a security researcher on September 17, 2026.
‎September 17, 2026
Threat actors used an unauthenticated remote code execution vulnerability in SolarWinds Access Rights Manager to target the software.
tactic Remote Code Execution
‎Sep 19, 2026
Threat actors exploited critical Remote Code Execution (RCE) flaws in SolarWinds patches for Observability and Self-Hosted products.
‎2026/09/24
Threat actors exploited a hardcoded static key in SolarWinds's Access Rights Manager (ARM) versions up to 2026.2, allowing for unauthenticated remote code execution (RCE).
organisation Observability Self-Hosted
organisation CVE-2026
organisation Vulnerability / Identity Security
organisation Access Rights
infrastructure 8.8
infrastructure 2026.2
organisation SolarWinds’s Access Rights
organisation CVSS
organisation SolarWinds
organisation Microsoft
organisation Revealing Identity
organisation WHD
organisation DoS
organisation Armadin
Tactical Metrics
Metrics
infrastructure
‎2026.2.2
Software Version
Metrics
infrastructure
‎2026.2.3
Software Version
Metrics
infrastructure
‎8.8
Software Version
Metrics
infrastructure
‎2026.2
Software Version
Intelligence Sources