SolarWinds Patches Critical Unauthenticated RCE Vulnerabilities

SolarWinds released patches for CVE-2026-28324 and CVE-2026-28325, two critical unauthenticated RCE flaws in Observability Self-Hosted platform.
Table of Contents
    Add a header to begin generating the table of contents

    SolarWinds released patches on September 24, 2026, addressing CVE-2026-28324 and CVE-2026-28325, two critical remote code execution vulnerabilities in SolarWinds Observability Self-Hosted platform. Both flaws can be exploited without authentication, and SolarWinds customers are advised to update immediately given the vendor’s history as a high-value target for sophisticated threat actors.

    CVE-2026-28324 and CVE-2026-28325: Unauthenticated RCE in Observability Platform

    The two vulnerabilities target SolarWinds Observability Self-Hosted, the company’s infrastructure monitoring and observability product that organizations use to track system performance, application health, and network activity across their IT environments. Both CVE-2026-28324 and CVE-2026-28325 are rated critical severity, indicating that successful exploitation can result in complete system compromise with minimal attacker effort or prerequisite access.

    The unauthenticated nature of both flaws significantly elevates their risk. Attackers do not need stolen credentials, prior system access, or user interaction to exploit the vulnerabilities—they can achieve remote code execution simply by reaching the vulnerable SolarWinds Observability instance over the network. For infrastructure monitoring platforms that typically have broad visibility into an organization’s systems and often run with elevated privileges to collect telemetry data, unauthenticated RCE represents a direct path to widespread network compromise.

    SolarWinds as High-Value APT Target

    The critical severity rating and unauthenticated exploitation path take on additional significance given SolarWinds’ history as a target for advanced persistent threat actors. The company’s infrastructure monitoring products are deployed across government agencies, critical infrastructure operators, and large enterprises, making any vulnerability in SolarWinds software a high-value target for nation-state espionage groups seeking access to sensitive networks.

    A successful compromise of a SolarWinds Observability platform could provide attackers with visibility into an organization’s entire infrastructure—every monitored system, application, and network device appears in the observability platform’s data streams. Beyond reconnaissance value, the access and credentials required for infrastructure monitoring can enable lateral movement to the systems being monitored, turning the observability platform into a launching point for broader network compromise.

    Patch Release Timeline and Customer Update Requirements

    SolarWinds released patches for both vulnerabilities on September 24, 2026. The disclosure does not indicate whether the vulnerabilities were discovered through internal security audits, external security research, or evidence of active exploitation. The lack of public exploitation details at the time of disclosure suggests either responsible disclosure by security researchers or internal discovery, though organizations should not assume the vulnerabilities were not independently discovered by threat actors.

    Customers running SolarWinds Observability Self-Hosted must apply the September 24 patches immediately. The unauthenticated RCE classification means these vulnerabilities pose an immediate risk to any Internet-facing or network-accessible Observability instance, and the SolarWinds brand name alone makes these systems attractive targets for reconnaissance and exploitation by multiple threat actor groups.

    Observability Platform Security and Privileged Access Implications

    Infrastructure monitoring and observability platforms occupy a unique security position: they require broad access and elevated privileges to collect telemetry from across an organization’s environment, but they also aggregate sensitive operational data that reveals system architectures, access patterns, and potential vulnerabilities. This combination of broad access and valuable data makes observability platforms high-value targets that demand security controls proportional to the access they possess.

    The unauthenticated RCE vulnerabilities in SolarWinds Observability highlight the risk of running monitoring infrastructure with Internet exposure or insufficient network segmentation. Observability platforms should typically operate within protected network segments with restricted access paths, not as Internet-facing services. Organizations that deployed SolarWinds Observability with external network reachability face higher risk from these vulnerabilities than those that restricted access to internal networks or VPN-only connections.

    Post-Patch Recommendations for SolarWinds Customers

    Beyond applying the September 24 patches, SolarWinds Observability customers should review their deployment architectures to minimize future exposure. Network segmentation that places observability infrastructure behind multiple layers of access control reduces the attack surface available to unauthenticated attackers. Regular credential rotation for monitoring service accounts limits the value of credentials that might be extracted from a compromised observability platform, and audit logging that tracks access to observability data can help detect unauthorized reconnaissance or data exfiltration.

    Organizations should also review access logs for SolarWinds Observability instances to identify any suspicious access patterns between the vulnerability introduction date and the September 24 patch release. While the disclosure does not specify when the vulnerabilities were introduced or whether active exploitation has occurred, the unauthenticated nature and critical severity mean any unusual access to Observability platforms warrants investigation. Indicators might include unexpected administrative actions, unusual telemetry queries, or access from unfamiliar IP addresses or user agents.

    The SolarWinds disclosure comes at a time when infrastructure monitoring and observability platforms face increasing attention from security researchers and threat actors alike. The operational necessity of these systems—organizations depend on them to maintain visibility into complex, distributed environments—makes them difficult to disable or restrict, creating persistent attack surfaces that must be defended through vigilant patching, access controls, and monitoring for compromise.

    Related Posts