SolarWinds has 3 CVEs on record. 3 were published in the last 90 days. The busiest recent month was September 2026 with 3. The median CVSS is 8.8 (high), with 1 rated critical. Most affected products: Observability Self-Hosted (2), Access Rights Manager (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.8
- Publish → KEV
- —
- Last 90 days
- 3 prev 0
Products
- Observability Self-Hosted 2
- Access Rights Manager 1
Worst active — by depth score
CVE-2026-28324Critical· 9.8SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability due to the insufficient integrity checks54CVE-2026-28326High· 8.8SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability49CVE-2026-28325High· 8.8SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability stemming from deserialization of untrusted data when the application is configured to use a specific communication mode.48
SolarWinds vulnerabilities
CVEs affecting SolarWinds, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-28325High· 8.8SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability stemming from deserialization of untrusted data when the application is configured to use a specific communication mode.
SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability stemming from deserialization of untrusted data when the application is configured to use a specific communication mode.
CVE-2026-28324Critical· 9.8SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability due to the insufficient integrity checks
SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability due to the insufficient integrity checks. Installations configured in a non-default and non-secure configuration are …
CVE-2026-28326High· 8.8SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability
SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability. The issue stems from a hardcoded static key.