SolarWinds has released Observability Self-Hosted 2026.2.3 to address two significant vulnerabilities that could enable unauthenticated attackers to remotely execute code on affected servers This article explores solarwinds released observability. . The update was released on September 22, 2026, and is crucial for organizations running SolarWinds Observability Self-Hosted in environments with Web Performance Monitor (WPM) players.

Exploitation of these vulnerabilities could allow remote attackers to run arbitrary commands on a vulnerable server without requiring authentication. However, the high severity score suggests that defenders should prioritize patching exposed and specially configured servers. SolarWinds has addressed these issues in version 2026.2.3, which includes security fixes and platform reliability improvements without adding new product features. Administrators should upgrade their entire SolarWinds deployment through Settings > My Deployment, which updates SolarWinds Platform products and related scalability engines.

Organizations should review server exposure, limit management access to trusted networks, monitor SolarWinds application and Windows logs for unexpected process execution, and investigate unusual activity involving polling engines or WPM players. Older deployments require extra attention: SolarWinds has ended engineering support for Observability Self-Hosted 2024.2 and earlier versions, meaning these versions no longer receive regular fixes or service releases.