Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
SolarWinds Vulnerabilities Enable Remote Code Execution

SolarWinds Vulnerabilities Enable Remote Code Execution

Posted on September 23, 2026 By CWS

SolarWinds has issued a crucial update for its Observability Self-Hosted software, version 2026.2.3, addressing two severe security vulnerabilities. These flaws, identified as CVE-2026-28324 and CVE-2026-28325, allow unauthenticated attackers to execute code remotely on compromised servers. The vulnerabilities are present in specific non-default configurations and communication modes.

Update Released Following Critical Discovery

The update, made available on September 22, 2026, is essential for organizations utilizing SolarWinds Observability Self-Hosted, particularly those operating in environments with Web Performance Monitor (WPM) players. Exploiting these vulnerabilities could enable attackers to execute arbitrary commands without authentication, putting system security at significant risk.

CVE-2026-28324 is notably serious, receiving a 9.8 out of 10 on the CVSS severity scale. This underscores the necessity for immediate attention by IT security teams to patch affected systems.

Understanding the Risks Involved

The vulnerabilities arise from inadequate integrity checks in non-default, unsecured configurations of the Observability Self-Hosted installations. Although the advisory does not include a public proof-of-concept, the high severity of these issues highlights the need for prioritizing patches for exposed servers.

The second vulnerability, CVE-2026-28325, also poses a significant threat with a CVSS score of 8.8. It involves the unsafe deserialization of untrusted data, which occurs when software processes serialized data controlled by an attacker without adequate validation.

Security Enhancements and Recommendations

Both vulnerabilities were responsibly reported by Kai Huang of Armadin, and SolarWinds has addressed these issues in the 2026.2.3 release. While the update does not introduce new features, it includes vital security fixes and improvements in platform reliability.

The update modifies the behavior of WPM player deployments. Passive players installed by default on the main polling engine will transition to player-initiated communication. Remote passive players will receive strong, randomly generated passwords during the upgrade.

Administrators are advised to upgrade the full SolarWinds deployment via the Settings > My Deployment menu. This action will update all related SolarWinds Platform products and scalability engines. Security teams should ensure that all components, including remote players with disabled automatic upgrades, are updated manually.

Additionally, organizations should assess server exposure, restrict management access to trusted networks, and monitor logs for unusual activity. Systems running older versions, such as Observability Self-Hosted 2024.2 and earlier, no longer receive support and should be upgraded immediately.

In summary, addressing these vulnerabilities promptly is crucial to maintaining security and integrity within affected systems. Organizations are encouraged to implement these updates to safeguard against potential threats.

Cyber Security News Tags:CVE, Cybersecurity, data protection, IT security, network security, remote code execution, security update, software patching, SolarWinds, Vulnerabilities

Post navigation

Previous Post: Adobe Issues Patches for Critical Security Flaws
Next Post: Critical cPanel Vulnerabilities Allow Root Access and Server Control

Related Posts

Critical IDIS IP Cameras One-Click Vulnerability Leads to full Compromise of Victim’s Computer Critical IDIS IP Cameras One-Click Vulnerability Leads to full Compromise of Victim’s Computer Cyber Security News
Critical Vulnerabilities in Enterprise Java Platforms Uncovered Critical Vulnerabilities in Enterprise Java Platforms Uncovered Cyber Security News
TP-Link Network Video Recorder Vulnerability Let Attackers Execute Arbitrary Commands TP-Link Network Video Recorder Vulnerability Let Attackers Execute Arbitrary Commands Cyber Security News
Critical Imunify360 AV Vulnerability Exposes 56 Million Linux-hosted Websites to RCE Attacks Critical Imunify360 AV Vulnerability Exposes 56 Million Linux-hosted Websites to RCE Attacks Cyber Security News
Uppsala Security Joins Cyber Threat Alliance for Blockchain Insight Uppsala Security Joins Cyber Threat Alliance for Blockchain Insight Cyber Security News
IBM AIX Vulnerabilities Let Remote Attacker Execute Arbitrary Commands IBM AIX Vulnerabilities Let Remote Attacker Execute Arbitrary Commands Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI Adoption in OT Security Grows, Full Autonomy Still Uncommon
  • Critical cPanel Vulnerabilities Allow Root Access and Server Control
  • SolarWinds Vulnerabilities Enable Remote Code Execution
  • Adobe Issues Patches for Critical Security Flaws
  • Malicious Streaming App Threatens Android Devices

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI Adoption in OT Security Grows, Full Autonomy Still Uncommon
  • Critical cPanel Vulnerabilities Allow Root Access and Server Control
  • SolarWinds Vulnerabilities Enable Remote Code Execution
  • Adobe Issues Patches for Critical Security Flaws
  • Malicious Streaming App Threatens Android Devices

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark