Critical SolarWinds Flaws Let Attackers Remotely Execute Code on Observability Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


SolarWinds released Observability Self-Hosted 2026.2.3 to fix two serious vulnerabilities that could let unauthenticated attackers remotely execute code on affected observability servers. The flaws, tracked as CVE-2026-28324 and CVE-2026-28325, affect specific non-default configurations and communication modes.

The update was released on September 22, 2026, and is especially important for organizations running SolarWinds Observability Self-Hosted in environments with Web Performance Monitor, or WPM, players.

Successful exploitation could let a remote attacker run arbitrary commands on a vulnerable server without logging in first. CVE-2026-28324 is rated 9.8 out of 10 on the CVSS severity scale, making it a critical issue.

SolarWinds said the vulnerability stems from insufficient integrity checks in Observability Self-Hosted installations configured in a non-default, non-secure manner.

SolarWinds Flaws Execute Code

The advisory does not provide public proof-of-concept details. However, the high severity score indicates that defenders should treat exposed and specially configured servers as high-priority patching targets. The second flaw, CVE-2026-28325, has a CVSS score of 8.8 and is also classified as an unauthenticated remote code execution issue.

According to SolarWinds, it stems from deserializing untrusted data when the application uses a specific communication mode. Unsafe deserialization occurs when software accepts attacker-controlled serialized data and processes it without proper validation, potentially allowing malicious objects or commands to run in the application context.

Kai Huang of Armadin responsibly reported both vulnerabilities. SolarWinds said the issues are resolved in version 2026.2.3, which adds no new product features but includes security fixes and platform reliability improvements.

The release also changes the behavior of certain WPM player deployments. After the upgrade, passive WPM players installed by default on the main polling engine are switched from server-initiated to player-initiated communication.

Remote passive WPM players are automatically assigned randomly generated strong passwords during their upgrade. However, SolarWinds noted that players with the Enable Upgrade option disabled are not upgraded automatically and require administrator attention. Active, player-initiated WPM players do not require a password after the upgrade.

Administrators should upgrade their entire SolarWinds deployment through Settings > My Deployment, which updates SolarWinds Platform products and related scalability engines.

Before applying the update, security teams should identify all main polling engines, remote WPM players, and communication modes in use.

They should also verify that passive remote players have strong credentials and that systems excluded from automatic upgrades are updated manually.

Organizations should review server exposure, restrict management access to trusted networks, monitor SolarWinds application and Windows logs for unexpected process execution, and investigate abnormal activity involving polling engines or WPM players.

Older deployments deserve particular attention: SolarWinds has ended engineering support for Observability Self-Hosted 2024.2 and earlier versions, meaning they no longer receive regular fixes or service releases.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post Critical SolarWinds Flaws Let Attackers Remotely Execute Code on Observability Servers appeared first on Cyber Security News.