# SolarWinds patches two remote code execution flaws in observability servers

_Published Wednesday, September 23, 2026 at 12:22 PM EDT · Security, Infrastructure · Latest · Tier 2 — Notable_

![SolarWinds patches two remote code execution flaws in observability servers — Primary](https://cybersecuritynews.com/wp-content/uploads/2026/09/Critical-SolarWinds-Flaws-Let-Attackers-Remotely-Execute-Code-on-Observability-Servers.webp)

SolarWinds released Observability Self-Hosted 2026.2.3 on September 22 to fix two vulnerabilities that could let attackers run code remotely without logging in. The flaws, CVE-2026-28324 and CVE-2026-28325, affect installations using specific non-default configurations or communication modes.

One flaw involves insufficient integrity checks; the other involves processing untrusted data in a way that could execute commands. The update also changes communication settings for some Web Performance Monitor players and assigns strong passwords to upgraded remote passive players. Players excluded from automatic upgrades need administrator attention. The report describes the potential for exploitation but does not identify an attack using either flaw.

## Sources

- [cybersecuritynews.com](https://cybersecuritynews.com/solarwinds-flaws-execute-code-on-observability-servers/)

---
Canonical: https://techandbusiness.org/newswire/TU7cgmXlBrKrRTb-9KbplL
Published: 2026-09-23T16:22:11.637Z
Story chronology: 2026-09-22T00:00:00.000Z
Retrieved: 2026-09-23T17:55:20.579Z
Publisher: Tech & Business (techandbusiness.org)
