Skip to main content

Share story

Security Infrastructure

SolarWinds patches two remote code execution flaws in observability servers

SolarWinds patches two remote code execution flaws in observability servers Image: Primary
SolarWinds released Observability Self-Hosted 2026.2.3 on September 22 to fix two vulnerabilities that could let attackers run code remotely without logging in. The flaws, CVE-2026-28324 and CVE-2026-28325, affect installations using specific non-default configurations or communication modes. One flaw involves insufficient integrity checks; the other involves processing untrusted data in a way that could execute commands. The update also changes communication settings for some Web Performance Monitor players and assigns strong passwords to upgraded remote passive players. Players excluded from automatic upgrades need administrator attention. The report describes the potential for exploitation but does not identify an attack using either flaw.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from cybersecuritynews.com and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Products
Products

Bird.com raises $450 million in JPMorgan-led debt financing

Bird.com, a customer messaging company, raised $450 million in debt financing led by JPMorgan Chase & Co., Bloomberg reported. The company is seeking to return cash to its investors and employees. The transaction adds debt capital...

Capital Infrastructure
Capital Infrastructure

Hubble Network raises $200 million for satellite Bluetooth network

Satellite startup Hubble Network raised $200 million in a new funding round, Bloomberg reported, taking its valuation to $1.6 billion. The company is working on a network of spacecraft intended to provide global Bluetooth connecti...

Security Infrastructure
Security Infrastructure

Analysis identifies two flaws behind exploited MikroTik router takeover chain

CERT Polska has identified the two RouterOS SSH flaws behind a previously reported attack that can give intruders administrative control of exposed MikroTik routers without completing authentication. One flaw lets a connection rea...

Security Infrastructure
Security Infrastructure

F5 patches exploited BIG-IP APM flaw as U.S. agencies face Friday deadline

F5 has released security updates for a critical BIG-IP APM flaw that it says attackers have exploited to run code remotely. BIG-IP APM manages access to organizational networks and applications. The vulnerability affects configura...

Robotics Capital
Robotics Capital

Tekever reaches first close of funding round targeting $580 million

Portuguese surveillance drone developer Tekever has reached the first close of a funding round targeting $580 million, Bloomberg reports. The company is seeking acquisitions following that close. The $580 million figure is the tar...

Infrastructure AI
Infrastructure AI

German and Dutch agencies launch €40 million AI chip design challenge

Germany's SPRIND and the Netherlands' NADI have launched a joint €40 million challenge to fund European AI chip design. The agencies plan to select seven teams for an initial stage, awarding each €2.6 million, then advance three t...