[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f7rUbzWdfkMidwfZB3iukgWisc17NXXICUj39C605rG0":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":42},"1a49521e-35f6-4dcf-8c74-735774d34abb","critical-unauthenticated-rce-flaws-patched-in-solarwinds-observability","87662ef9-0b1c-466b-9add-7663db26c824","Critical Unauthenticated RCE Flaws Patched in SolarWinds Observability","SolarWinds disclosed two critical remote code execution vulnerabilities (CVE-2026-28324 and CVE-2026-28325) in its Observability Self-Hosted product, both exploitable without any authentication by a remote attacker. The near-perfect CVSS scores (9.8 and 8.8) reflect the severity: no credentials, no user interaction, and full code execution potential. This follows a pattern of critical RCE flaws in SolarWinds products — a vendor already under heightened scrutiny since the 2020 supply chain attack — underscoring the importance of rapid patch cycles for network management and monitoring tools. Because these products often sit at the heart of IT infrastructure with broad network access, a successful exploit could give attackers a powerful pivot point into the entire environment.","**Immediate actions:**\n- Apply SolarWinds patches upgrading Observability Self-Hosted beyond version 2026.2.2 without delay.\n- Restrict network access to the Observability Self-Hosted management interface using firewall rules to trusted IP ranges only.\n- Audit all SolarWinds products in your environment for additional unpatched RCE vulnerabilities, including Access Rights Manager.\n\n**Long-term improvements:**\n- Establish a formal emergency patching SLA (e.g., 24–48 hours) for CVSS 9.0+ vulnerabilities affecting internet-facing or management-plane systems.\n- Maintain a continuously updated asset inventory that maps every SolarWinds (and third-party) product version to known CVEs.\n- Implement network segmentation to isolate monitoring and observability platforms from production workloads and the public internet.\n\n**Detection measures:**\n- Deploy IDS\u002FIPS rules and WAF signatures targeting known exploit patterns for these CVEs as a compensating control until patches are applied.\n- Enable detailed logging on SolarWinds platforms and ship logs to a SIEM to detect anomalous unauthenticated access attempts in real time.\n- Subscribe to SolarWinds security advisories and CISA KEV alerts to receive immediate notification of newly disclosed vulnerabilities.",[12,13,14,15,16,17,18,19,20,21],"CIS Control 7: Continuous Vulnerability Management","CIS Control 12: Network Infrastructure Management","CIS Control 13: Network Monitoring and Defense","NIST SP 800-40 Rev. 4: Patch Management","NIST SI-2: Flaw Remediation","NIST SC-7: Boundary Protection (Network Segmentation)","NIST RA-5: Vulnerability Monitoring and Scanning","NIST IR-6: Incident Reporting","CISA KEV Catalog: Known Exploited Vulnerabilities Remediation Guidance","ITIL Change Management: Emergency Change Procedure","published","2026-09-24T12:21:28.876378+00:00","2026-09-24T12:21:28.525+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fwww.securityweek.com\u002Fsolarwinds-patches-critical-rce-flaws-in-observability-self-hosted\u002F","solarwinds-patches-critical-rce-flaws-in-observability-self-hosted-8a7204","SolarWinds Patches Critical RCE Flaws in Observability Self-Hosted",[30,36],{"id":31,"name":32,"slug":33,"description":34,"color":35},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":37,"name":38,"slug":39,"description":40,"color":41},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[43],{"id":44,"date":45,"edition":46,"title":47,"audio_url":48},"017e15f4-302e-4b63-b0fb-7c746cec3f56","2026-09-24","afternoon","ThreatNoir Afternoon Brief — September 24","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-09-24\u002Fthreatnoir-afternoon-brief-2026-09-24.mp3"]