SolarWinds Security in 2026: What NCM Buyers Should Actually Check
Six years on from SUNBURST, "is this vendor secure?" is still the wrong question. Here is what a self-hosted NCM buyer should check instead, and what running config management on your own infrastructure does and does not change.

Ask most network teams about SolarWinds security and you get one answer: SUNBURST, December 2020. It was a serious supply chain compromise and it deserved the attention it got. It is also six years old, and it is no longer the useful question.
The useful question for anyone buying or replacing a network configuration management platform is narrower and more practical. Your NCM tool holds privileged credentials for every device on your network and a complete history of how those devices are configured. That is one of the highest value targets in your estate. So what should you actually be checking, in any vendor, including this one?
What to check in any NCM vendor
1. Do they publish security advisories at all?
Not whether they have ever had a vulnerability. Every non-trivial codebase has them. The question is whether the vendor tells you when they find one, and how fast.
SolarWinds does this properly. They run a public security advisories page and a Trust Center, and they publish under a Secure by Design programme built out after 2020. Whatever else is true about the 2020 incident, their disclosure practice today is not the weak point.
rConfig publishes its own security advisories and a security policy, for the same reason. A vendor that has never published an advisory has either never looked or is not telling you.
2. Where do the device credentials live?
This is the one that actually separates architectures, and it gets less attention than it should.
If your NCM platform is SaaS, your device credentials and your full configuration history sit in the vendor's infrastructure. That can be perfectly well run. It is still a dependency you do not control, and in a supply chain compromise it is the vendor's blast radius, not yours.
Self-hosted changes the shape of that risk rather than removing it. Credentials and config history stay on infrastructure you own, inside your own network boundary, under your own access controls. You also inherit the responsibility for patching and hardening it. That is a real trade, not a free win, and anyone selling it to you as a free win is overselling.
3. What is the update path, and how quickly can you take one?
A patch you cannot deploy is not a patch. Ask how updates are delivered, whether they require downtime, and whether a security fix can ship independently of a feature release. Tools that bundle security fixes into large annual upgrades leave you exposed for months at a time, regardless of how quickly the vendor writes the fix.
4. Is configuration management the product, or a module?
Not a security question on its face, but it becomes one. In a large platform, the config module competes for engineering attention with everything else in the suite. Ask how many releases the configuration component specifically has had in the last year.
What this means if you are looking at SolarWinds NCM
SolarWinds Network Configuration Manager is active and currently sold within SolarWinds Observability Self-Hosted, and also as a standalone Orion module. It is a capable product with a large installed base. It is not end of life and nobody should tell you otherwise.
The reasons teams move off it in 2026 are mostly commercial and architectural rather than security related: node based licensing across the DL50 to DLX tiers, a platform you may only want one component of, and a Windows Server deployment where the rest of the estate is Linux. We cover that comparison honestly, including what rConfig does not replace, on our SolarWinds NCM alternative page.
If security is genuinely your driver, be specific about which part. "Reduce the number of vendors holding privileged credentials" is a real requirement you can design around. "Get away from SolarWinds because of 2020" is not, and it will lead you to a worse decision.
Where rConfig sits
rConfig is self-hosted on Linux. Device credentials, configuration backups and change history stay on your infrastructure. Core is free and open source, so the code handling those credentials can be read by anyone who wants to read it, which is a meaningful property for a tool in this position.
We publish advisories, we document our security policy, and we would rather you checked both than took our word for it.
Book a walkthrough if you want to go through any of this against your own environment.
Sources checked 14 September 2026: SolarWinds security advisories, SolarWinds Network Configuration Manager. Product details are taken from the SolarWinds site on that date and may change.
About the Author
rConfig
All at rConfig
The rConfig Team is a collective of network engineers and automation experts. We build tools that manage millions of devices worldwide, focusing on speed, compliance, and reliability.
More about rConfig Team
