On September 22, 2026, SolarWinds published two advisories for Observability Self-Hosted. France's CERT-FR relayed them the next day, describing arbitrary remote code execution risk in versions before 2026.2.3.
Monitoring platforms often have privileged visibility into servers, service accounts and network flows. This article does not establish compromise of every deployment; it does justify a quick inventory and access review.
The published scope
The two SolarWinds notices cover CVE-2026-28324 and CVE-2026-28325. CERT-FR identifies versions before 2026.2.3 and points to the vendor bulletins for the exact remediation.
Start by finding every Self-Hosted instance, including test environments and installations managed by a supplier. Record the running version, not only the package version downloaded.
Why monitoring matters
A monitoring tool collects metrics, contacts agents and may store technical credentials. Code execution at this layer can extend into observed systems depending on service permissions and network segmentation.
That is a risk analysis, not a claim about exploitation in your environment. It explains why an “internal” administration component still deserves urgent treatment.
Patch and verify
Apply 2026.2.3 or the SolarWinds fix specified for your edition, then confirm each node restarted on the intended version. Temporarily restrict administration to required networks without losing collection needed for response.
Preserve logs before rotation. Look for unusual connections, configuration changes, new service accounts and unexpected outbound traffic from the Observability host.
Access and secrets
Map the secrets read by the application: probe accounts, SSH access, APIs, databases and ticketing integrations. If exploitation is plausible, rotate relevant values after preserving investigation evidence.
Do not automatically delete accounts or logs. The remediation sequence should distinguish an upgrade error from hostile activity.
The Soclyde connection
Soclyde does not secure SolarWinds and does not replace segmentation or monitoring. It can help keep a local-first encrypted inventory of monitoring access and generate distinct values during rotation.
The benefit is operational: find the right secret and its users without copying it into scripts or crisis chats. The vendor fix remains essential.
Key takeaways
Two SolarWinds vulnerabilities enable remote code execution before Observability Self-Hosted 2026.2.3. Inventory, patch, preserve logs and rotate exposed access. Read the secure password generator guide or contact Soclyde.



