Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4501 articles · 223832 vulns · 37/41 feeds (7d)
← Back to list
9.8
CVE-2026-28324PATCHED
solarwinds · observability self-hosted

SolarWinds Observability Self-Hosted Remote Code Execution Vulnerability

Description

SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability due to the insufficient integrity checks. Installations configured in a non-default and non-secure configuration are affected.

Affected Products

VendorProductVersions
solarwindsobservability self-hosted0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
solarwindsplatformcert_advisory90%

References

  • https://documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/hco_2026-2-3_release_notes.htm(release-notes)
  • https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28324(vendor-advisory)
  • https://documentation.solarwinds.com/en/success_center/orionplatform/content/core-secure-configuration.htm(x_secure-configuration-guide)
  • https://documentation.solarwinds.com/en/success_center/wpm/content/orionwpmagaddingalocation.htm(mitigation)

Related News (5 articles)

Tier D
Heise Security3d ago
Sicherheitspatch gegen Schadcode repariert SolarWinds Observability Self-Hosted
→ No new info (linked only)
Tier B
CCCS Canada4d ago
SolarWinds security advisory (AV26-950)
→ No new info (linked only)
Tier B
BSI Advisories4d ago
[NEU] [hoch] SolarWinds Platform (Observability Self-Hosted): Mehrere Schwachstellen ermöglichen Codeausführung
→ No new info (linked only)
Tier B
CERT-FR5d ago
Multiples vulnérabilités dans SolarWinds Observability Self-Hosted (23 septembre 2026)
→ No new info (linked only)
Tier C
VulDB5d ago
CVE-2026-28324 | SolarWinds Observability Self-Hosted up to 2026.2.2 privileges management
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.19.8 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
2026.2.3
CWECWE-345
PublishedSep 22, 2026
Trending Score44
Source articles5
Independent5
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-28326
SolarWinds Access Rights Manager Unauthenticated Remote Code Execution Vulnerability
Trending: 38
HIGHCVE-2026-28325
SolarWinds Observability Self-Hosted Unauthenticated Remote Code Execution Vulnerability
Trending: 35
MEDIUMCVE-2026-28315
SolarWinds Serv-U Authenticated Stored Cross-site Scripting (XSS) Vulnerability
CRITICALCVE-2026-28302
SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability
CRITICALCVE-2026-28305
SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 22, 2026
Discovered by ZDM
Sep 22, 2026
Patch Available
Sep 22, 2026