SOCLYDE logo
Current languageEN
Cybersecurity newsVulnerabilitySolarWindsInfrastructure

Solarwinds observability: patch two critical rce flaws

CVE-2026-28324 and CVE-2026-28325 allow remote code execution in Observability Self-Hosted before 2026.2.3.

By Soclyde Team

An empty network operations room during a maintenance window

In summary

  • SolarWinds Observability Self-Hosted before 2026.2.3 is affected by two vulnerabilities that allow remote code execution.
  • SolarWinds advisories dated September 22 and France's CERT-FR recommend the vendor fix.
  • Inventory instances, preserve logs and rotate access if an instance was exposed.

Explore next

Soclyde resources

Article contents

On September 22, 2026, SolarWinds published two advisories for Observability Self-Hosted. France's CERT-FR relayed them the next day, describing arbitrary remote code execution risk in versions before 2026.2.3.

Monitoring platforms often have privileged visibility into servers, service accounts and network flows. This article does not establish compromise of every deployment; it does justify a quick inventory and access review.

The published scope

The two SolarWinds notices cover CVE-2026-28324 and CVE-2026-28325. CERT-FR identifies versions before 2026.2.3 and points to the vendor bulletins for the exact remediation.

Start by finding every Self-Hosted instance, including test environments and installations managed by a supplier. Record the running version, not only the package version downloaded.

Why monitoring matters

A monitoring tool collects metrics, contacts agents and may store technical credentials. Code execution at this layer can extend into observed systems depending on service permissions and network segmentation.

That is a risk analysis, not a claim about exploitation in your environment. It explains why an “internal” administration component still deserves urgent treatment.

Patch and verify

Apply 2026.2.3 or the SolarWinds fix specified for your edition, then confirm each node restarted on the intended version. Temporarily restrict administration to required networks without losing collection needed for response.

Preserve logs before rotation. Look for unusual connections, configuration changes, new service accounts and unexpected outbound traffic from the Observability host.

Access and secrets

Map the secrets read by the application: probe accounts, SSH access, APIs, databases and ticketing integrations. If exploitation is plausible, rotate relevant values after preserving investigation evidence.

Do not automatically delete accounts or logs. The remediation sequence should distinguish an upgrade error from hostile activity.

The Soclyde connection

Soclyde does not secure SolarWinds and does not replace segmentation or monitoring. It can help keep a local-first encrypted inventory of monitoring access and generate distinct values during rotation.

The benefit is operational: find the right secret and its users without copying it into scripts or crisis chats. The vendor fix remains essential.

Key takeaways

Two SolarWinds vulnerabilities enable remote code execution before Observability Self-Hosted 2026.2.3. Inventory, patch, preserve logs and rotate exposed access. Read the secure password generator guide or contact Soclyde.

Frequently asked questions

Which versions are affected?

CERT-FR identifies Observability Self-Hosted versions before 2026.2.3. Check both SolarWinds bulletins for your edition and upgrade path.

Is an internal instance safe?

No. An internal instance may be reached through the monitoring network or a compromised account. Restrict access, patch and review logs.

Should passwords be changed?

If exploitation is plausible, list the secrets available to the service and rotate those covering the instance, probes and managed systems.

References

Sources and references

Need advice?

Design your password strategy with Soclyde

Schedule a dedicated walkthrough with the team to see how local-first security adapts to your stack.

Talk with us

Keep reading