SolarWinds has taken action to secure its Observability Self-Hosted solution by releasing patches for two critical vulnerabilities that could allow remote code execution. These vulnerabilities, identified as CVE-2026-28324 and CVE-2026-28325, affect all versions of Observability Self-Hosted up to 2026.2.2 and have been resolved in version 2026.2.3. The first vulnerability, with a CVSS score of 9.8, arises from an insufficient integrity check. This flaw poses a risk to deployments using non-default, non-secure configurations. The second vulnerability, with a CVSS score of 8.8, involves the deserialization of untrusted data, impacting installations configured with a specific communication mode. Both vulnerabilities allow remote attackers to exploit them without needing authentication. SolarWinds has credited Kai Huang from Armadin for identifying these flaws. In addition, last week the company addressed another unauthenticated RCE vulnerability, CVE-2026-28326, in its Access Rights Manager. This was caused by a hardcoded static key in versions up to 2026.2. The company has not reported any active exploitation of these vulnerabilities in the wild. For more information, users can refer to the security advisories provided by SolarWinds.