CVE-2026-28324
SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability due to the insufficient integrity checks. Installations configured in a non-default and non-secure configuration are affected.
- Published Sep 22, 2026
- CVSS 9.8 critical
- 0.7% chance of exploitation in the next 30 days (EPSS)
Affected software
In the news
- ⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats The Hacker News ·
- SolarWinds security advisory (AV26-950) Canadian Centre for Cyber Security ·
- Multiple vulnerabilities in SolarWinds Observability Self-Hosted CERT-FR ·