Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
SolarWinds Fixes Major RCE Vulnerabilities in IT Software

SolarWinds Fixes Major RCE Vulnerabilities in IT Software

Posted on September 24, 2026 By CWS

SolarWinds has rolled out updates to address two significant vulnerabilities found in its Observability Self-Hosted software, which could potentially be used for remote code execution (RCE) attacks.

Understanding the Vulnerabilities

Observability Self-Hosted is designed to offer organizations comprehensive IT monitoring, configuration management, and security compliance. The first vulnerability, known as CVE-2026-28324 with a CVSS score of 9.8, arises from inadequate integrity checks. This flaw poses a risk in environments that do not use default or secure settings, potentially allowing unauthorized remote code execution.

The second issue, CVE-2026-28325, carries a CVSS score of 8.8 and involves the deserialization of untrusted data. This vulnerability affects systems configured to employ a specific communication mode, making them susceptible to attacks from remote, unauthenticated users.

Impact and Resolution

These security issues affect all versions of Observability Self-Hosted up to 2026.2.2, with fixes implemented in version 2026.2.3. SolarWinds acknowledges Kai Huang from Armadin for identifying and reporting these vulnerabilities.

Last week, an additional unauthenticated RCE vulnerability, CVE-2026-28326, was patched. This flaw impacted SolarWinds’s Access Rights Manager (ARM) due to a hardcoded static key present in versions up to 2026.2.

Security Implications and Future Outlook

SolarWinds has not reported any active exploitation of these vulnerabilities. Users are encouraged to review the detailed information available on the company’s security advisories page for guidance on protecting their systems.

With cybersecurity threats constantly evolving, it is crucial for organizations to stay informed about potential vulnerabilities and take proactive measures to secure their IT environments.

Security Week News Tags:Access Rights Manager, CVE-2026-28324, CVE-2026-28325, CVE-2026-28326, Cybersecurity, IT compliance, IT monitoring, IT security, Observability Self-Hosted, RCE, remote code execution, security patch, software update, SolarWinds, Vulnerabilities

Post navigation

Previous Post: Malicious Content Detected on Placeholder Domain
Next Post: Rogue AI Breach of Australian Medicare Portal Sparks Concern

Related Posts

Node.js Maintainers Targeted by North Korean Hackers Node.js Maintainers Targeted by North Korean Hackers Security Week News
Grandstream Phone Flaw Enables Call Interception Risk Grandstream Phone Flaw Enables Call Interception Risk Security Week News
Spektrum Labs Emerges From Stealth to Help Companies Prove Resilience Spektrum Labs Emerges From Stealth to Help Companies Prove Resilience Security Week News
Ivanti Releases Critical Zero-Day Patch for EPMM Ivanti Releases Critical Zero-Day Patch for EPMM Security Week News
US, Allies Alert on Russian Cyber Threats to Key Infrastructure US, Allies Alert on Russian Cyber Threats to Key Infrastructure Security Week News
Anthropic Enhances Claude AI with New Security Features Anthropic Enhances Claude AI with New Security Features Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Urgent Update: Roundcube Webmail SQL Flaw Exploited
  • Rogue AI Breach of Australian Medicare Portal Sparks Concern
  • SolarWinds Fixes Major RCE Vulnerabilities in IT Software
  • Malicious Content Detected on Placeholder Domain
  • Galago Ransomware Links to Panzer Group Unveiled

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Urgent Update: Roundcube Webmail SQL Flaw Exploited
  • Rogue AI Breach of Australian Medicare Portal Sparks Concern
  • SolarWinds Fixes Major RCE Vulnerabilities in IT Software
  • Malicious Content Detected on Placeholder Domain
  • Galago Ransomware Links to Panzer Group Unveiled

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark