INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
SolarWinds Patches Multiple Critical RCE Flaws in Observability Software
| 2026-09-24 10:40 CRITICAL LOW EXPLOITED VULNERABILITY VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
On September 24, 2026, SolarWinds released patches for two severe vulnerabilities in Observability Self-Hosted that could be exploited for remote code execution (RCE). The first flaw, tracked as CVE-2026-28324 with a CVSS score of 9.8, is an insufficient integrity check issue leading to RCE on deployments that run non-default and non-secure configurations. Tracked as CVE-2026-28325 with a CVSS score of 8.8, the second bug is described as a deserialization of untrusted data weakness affecting installations configured to use a specific communication mode. The vulnerabilities impact all Observability Self-Hosted versions up to 2026.2.2 and were addressed in version 2026.2.3. SolarWinds credited Kai Huang from Armadin for reporting both flaws, which can be exploited by remote attackers without authentication.
Technical Mitigations AI-generated
• Patch SolarWinds Observability Self-Hosted to version 2026.2.3 for the insufficient integrity check issue (CVE-2026-28324) and deserialization of untrusted data weakness (CVE-2026-28325).
• Update Access Rights Manager (ARM) to version 2026.2.1 to address the hard-coded static key vulnerability (CVE-2026-28326).
• Apply a patch for Serv-U to resolve privilege escalation, remote code execution, and administrator account creation vulnerabilities (CVE-2026-28302 through CVE-2026-28317, CVE-2026-28321, CVE-2026-28323).
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-28304CVE-2026-28304
CVE-2026-28321CVE-2026-28321
CVE-2026-28326CVE-2026-28326
CVE-2026-28324CVE-2026-28324
CVE-2026-28323CVE-2026-28323
CVE-2026-28299CVE-2026-28299
CVE-2026-28317CVE-2026-28317
CVE-2026-28302CVE-2026-28302
CVE-2026-28325CVE-2026-28325
Target & Sectors
Global Scope
Incident Timeline
2026.2.1
The critical Remote Code Execution (RCE) flaws in SolarWinds Observability Self-Hosted have been resolved in version WHD 2026.2.1.
2026.2.2
Threat actors exploited critical Remote Code Execution (RCE) flaws in Observability Self-Hosted versions up to 2026.2.2 before the patch was released in version 2026.2.3.
Click on any entity below to view its context and source!
infrastructure
2026.2.2
The vulnerabilities impact all Observability Self-Hosted versions up to 2026.2.2 and were addressed in version 2026.2.3.
infrastructure
2026.2.3
The vulnerabilities impact all Observability Self-Hosted versions up to 2026.2.2 and were addressed in version 2026.2.3.
2026/09/17
The company patched another unauthenticated Remote Code Execution (RCE) bug reported by a security researcher on September 17, 2026.
September 17, 2026
Threat actors used an unauthenticated remote code execution vulnerability in SolarWinds Access Rights Manager to target the software.
Click on any entity below to view its context and source!
tactic
Remote Code Execution
"SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability," SolarWinds said in an advisory released on September 17, 2026.
Sep 19, 2026
Threat actors exploited critical Remote Code Execution (RCE) flaws in SolarWinds patches for Observability and Self-Hosted products.
2026/09/24
Threat actors exploited a hardcoded static key in SolarWinds's Access Rights Manager (ARM) versions up to 2026.2, allowing for unauthenticated remote code execution (RCE).
Click on any entity below to view its context and source!
organisation
Observability Self-Hosted
SolarWinds has released patches for two severe vulnerabilities in Observability Self-Hosted that could be exploited for remote code execution (RCE).
organisation
CVE-2026
SolarWinds has also released fixes for 16 flaws impacting Serv-U (CVE-2026-28302, from CVE-2026-28304 through CVE-2026-28317, CVE-2026-28321, CVE-2026-28323) that could lead to privilege escalation, remote code execution, and the creation of administrator accounts.
organisation
Vulnerability / Identity Security
Ravie Lakshmanan
Sep 19, 2026
Vulnerability / Identity Security
SolarWinds has released security updates to address a high-severity flaw in Access Rights Manager (ARM) that, if successfully exploited, could lead to an unauthenticated remote code execution vulnerability.
organisation
Access Rights
Ravie Lakshmanan
Sep 19, 2026
Vulnerability / Identity Security
SolarWinds has released security updates to address a high-severity flaw in Access Rights Manager (ARM) that, if successfully exploited, could lead to an unauthenticated remote code execution vulnerability.
infrastructure
8.8
Tracked as CVE-2026-28326 (CVSS score of 8.8) and affecting SolarWinds’s Access Rights Manager (ARM), it exists because ARM versions up to 2026.2 contain a hardcoded static key.
infrastructure
2026.2
Tracked as CVE-2026-28326 (CVSS score of 8.8) and affecting SolarWinds’s Access Rights Manager (ARM), it exists because ARM versions up to 2026.2 contain a hardcoded static key.
The issue affects all versions of Access Rights Manager 2026.2 and prior.
organisation
SolarWinds’s Access Rights
Tracked as CVE-2026-28326 (CVSS score of 8.8) and affecting SolarWinds’s Access Rights Manager (ARM), it exists because ARM versions up to 2026.2 contain a hardcoded static key.
organisation
CVSS
The vulnerability, tracked as
CVE-2026-28326
, is rated 8.8 out of 10.0 on the CVSS scoring system.
organisation
SolarWinds
SolarWinds Patches Critical RCE Flaws in Observability Self-Hosted.
SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE.
organisation
Microsoft
:
Check Point Patches Exploited Management Server Zero-Day
Related:
Nightmare Eclipse Drops New Microsoft Defender Exploit
organisation
Revealing Identity
After Revealing Identity
organisation
WHD
The development comes nearly two months after the company
shipped
fixes for a critical flaw impacting Web Help Desk (WHD) (CVE-2026-28323, CVSS score: 9.8) that could result in a SAML authentication bypass when the SAML 2.0 authentication method is enabled.
organisation
DoS
Another vulnerability relates to a denial-of-service (DoS) vulnerability (CVE-2026-28299, CVSS score: 8.2) that could cause the Web Help Desk server to crash due to insufficient memory.
organisation
Armadin
"
The company credited Armadin security researcher Kai Huang with discovering and reporting the flaw, which has been
patched in ARM 2026.2.1
.
Tactical Metrics
Metrics
infrastructure
2026.2.2
Software Version
Click for context!
The vulnerabilities impact all Observability Self-Hosted versions up to 2026.2.2 and were addressed in version 2026.2.3.
Metrics
infrastructure
2026.2.3
Software Version
The vulnerabilities impact all Observability Self-Hosted versions up to 2026.2.2 and were addressed in version 2026.2.3.
Metrics
infrastructure
8.8
Software Version
Tracked as CVE-2026-28326 (CVSS score of 8.8) and affecting SolarWinds’s Access Rights Manager (ARM), it exists because ARM versions up to 2026.2 contain a hardcoded static key.
Metrics
infrastructure
2026.2
Software Version
Tracked as CVE-2026-28326 (CVSS score of 8.8) and affecting SolarWinds’s Access Rights Manager (ARM), it exists because ARM versions up to 2026.2 contain a hardcoded static key.
The issue affects all versions of Access Rights Manager 2026.2 and prior.
Intelligence Sources
The Hacker News
2026-09-19
SecurityWeek
2026-09-24
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-05T11:28
Comprehensive Tactical Telemetry
Highly Correlated Entities
12x
organisation
Identified Entity
Observability Self-Hosted
entity
9x
vulnerability
Exploited CVE
CVE-2026-28324
cve
6x
timeline
Temporal Reference
2026.2.2
date
4x
infrastructure
Software Version
2026.2.2
version
2x
tactic
Cyber Operation Type
Remote Code Execution
tactic
2x
vulnerability
CVSS Score
10
score
Contextual Telemetry
Context Block
9 METRICS
general metric
Arm
2,026
arm
tactic
MITRE ATT&CK Technique
T1584.004 - Server
technique
general metric
Flaws
16
flaws
general metric
Serv U
28,302
serv u
general metric
Sep
19
sep
general metric
Cve-2026
9
cve-2026
general metric
Cvss Score
10
cvss score
general metric
Authentication
2
authentication
general metric
Score
8
score
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.