{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3asolarwindsobservability_self-hosted/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:solarwinds:observability_self-hosted:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-28325"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["SolarWinds Observability Self-Hosted"],"_cs_severities":["high"],"_cs_tags":["vulnerability","rce","solarwinds"],"_cs_type":"advisory","_cs_vendors":["SolarWinds"],"content_html":"\u003cp\u003eSolarWinds Observability Self-Hosted contains an unauthenticated remote code execution (RCE) vulnerability identified as CVE-2026-28325. The flaw originates from the insecure deserialization of untrusted data processed by the application when it is configured to operate in a specific communication mode. This vulnerability allows an unauthenticated remote attacker to send specially crafted data to the application, which is then deserialized without adequate validation, leading to the execution of arbitrary code with the privileges of the application process. Given that SolarWinds observability components often run with elevated service accounts on critical infrastructure, successful exploitation could lead to full system compromise. Organizations running self-hosted instances should verify their current configuration against the vulnerability requirements provided by SolarWinds and prioritize patching or disabling the vulnerable communication mode until updates are applied.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-28325 allows a remote, unauthenticated attacker to execute arbitrary code on the underlying host, potentially leading to unauthorized data access, lateral movement within the network, and full compromise of the affected server.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify all SolarWinds Observability Self-Hosted instances in the environment.\u003c/li\u003e\n\u003cli\u003eReview SolarWinds security advisories to determine if your specific configuration utilizes the vulnerable communication mode.\u003c/li\u003e\n\u003cli\u003eApply patches provided by SolarWinds immediately upon release to remediate CVE-2026-28325.\u003c/li\u003e\n\u003cli\u003eMonitor web server and application logs for anomalous POST requests to internal API endpoints that may signify attempts to inject serialized objects.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-22T20:40:02Z","date_published":"2026-09-22T20:40:02Z","id":"https://feed.craftedsignal.io/briefs/2026-09-solarwinds-rce/","summary":"SolarWinds Observability Self-Hosted is vulnerable to unauthenticated remote code execution via insecure deserialization, allowing remote attackers to execute arbitrary code.","title":"Unauthenticated Remote Code Execution in SolarWinds Observability Self-Hosted","url":"https://feed.craftedsignal.io/briefs/2026-09-solarwinds-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:solarwinds:observability_self-Hosted:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}