SolarWinds has released patches for two critical remote code execution vulnerabilities in its Observability Self-Hosted product. The flaws, tracked as CVE-2026-28324 and CVE-2026-28325, can be exploited without authentication, according to SecurityWeek. That makes them especially dangerous, as an attacker would not need valid credentials to target affected deployments.

The vulnerabilities were disclosed in a SecurityWeek report, which did not provide technical details about the root cause or exploitability. The publication notes that the patches are available and urges administrators to apply them promptly. No workarounds or indicators of compromise were mentioned in the source.

Given SolarWinds' history as a high-profile supply-chain attack target, unauthenticated RCE flaws in its observability stack warrant immediate attention. Organizations running self-hosted instances should prioritize testing and deploying the update, and review their exposure if the product is reachable from untrusted networks.