SolarWinds has issued a critical security patch for its Observability Self-Hosted product after discovering malicious code embedded in the software. The company confirmed the issue in an advisory published on September 24, 2026.
The vulnerability specifically affects customers running Observability in self-hosted environments, rather than SaaS deployments. SolarWinds urged affected organizations to apply the patch immediately and review their systems for signs of compromise.
The incident adds to SolarWinds' troubled security history, which includes the devastating SUNBURST supply chain attack discovered in December 2020 that compromised thousands of organizations worldwide. While the current issue appears more contained, it underscores ongoing concerns about the security of self-hosted enterprise monitoring tools.
Organizations using SolarWinds Observability Self-Hosted should check their deployment versions against the published advisory and apply the remediation patches without delay. SolarWinds has not disclosed whether the malicious code was actively exploited in the wild prior to discovery.




