CVE-2026-28325
SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability stemming from deserialization of untrusted data when the application is configured to use a specific communication mode.
- Published Sep 22, 2026
- CVSS 8.8 high
- 1.5% chance of exploitation in the next 30 days (EPSS)
Affected software
In the news
- ⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats The Hacker News ·
- SolarWinds security advisory (AV26-950) Canadian Centre for Cyber Security ·
- Multiple vulnerabilities in SolarWinds Observability Self-Hosted CERT-FR ·