Summary
SolarWinds patched three vulnerabilities in its Observability Self-Hosted and Access Rights Manager products that allow unauthenticated remote code execution. These flaws could let attackers take full control of monitoring infrastructure and manipulate sensitive operational data.
Take Action:
If you run SolarWinds Observability Self-Hosted or Access Rights Manager, update ASAP, to version 2026.2.3 and 2026.2.1 respectively. Until you can patch, make sure these servers can't be reached from the internet and are accessible only from trusted internal networks, and treat any exposed instance as possibly compromised.
Read the full article on BeyondMachines
This article was originally published on BeyondMachines
Top comments (0)