Vulnerabilities & Exploits

SolarWinds ARM Patch Fixes Hard-Coded Key RCE

SolarWinds patched Access Rights Manager 2026.2.1 on September 17, fixing CVE-2026-28326, a high-severity flaw that could let an attacker reach unauthenticated remote code execution in ARM 2026.2 and earlier. SolarWinds credited Armadin researcher Kai Huang with finding it and said it has not reported exploitation in the wild.

The bug comes from a hard-coded static key: the product trusts the same built-in secret everywhere instead of proving each installation's identity separately, so a request that can use that key can be treated like an internal one and drive the application into code execution without a login. That makes this a product-secrets failure, not just a generic code bug.

For administrators running ARM, the exposure sits in the access-control layer itself, so a perimeter that blocks direct logins does not change the trust the product grants once the key is accepted. SolarWinds is also shipping fixes across WHD and Serv-U, which is a reminder that this vendor patch cycle is broader than one product.

1 source · Sep 19

CVE-2026-28326

NVD KEV

CVSS 8.8 HIGH: solarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability. EPSS 0.5% (45th percentile).

Timeline

Sources

Part of the PlainSec briefing for 2026-09-20

Every edition of this story: SolarWinds ARM Patch Fixes Hard-Coded Key RCE

More from today