CVE-2026-28326
CVSS 8.8 HIGH: solarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability. EPSS 0.5% (45th percentile).
Vulnerabilities · 2 days ago
SolarWinds patched Access Rights Manager 2026.2.1 on September 17, fixing CVE-2026-28326, a high-severity flaw that could let an attacker reach unauthenticated remote code execution in ARM 2026.2 and earlier. SolarWinds credited Armadin researcher Kai Huang with finding it and said it has not reported exploitation in the wild.
The bug comes from a hard-coded static key: the product trusts the same built-in secret everywhere instead of proving each installation's identity separately, so a request that can use that key can be treated like an internal one and drive the application into code execution without a login. That makes this a product-secrets failure, not just a generic code bug.
For administrators running ARM, the exposure sits in the access-control layer itself, so a perimeter that blocks direct logins does not change the trust the product grants once the key is accepted. SolarWinds is also shipping fixes across WHD and Serv-U, which is a reminder that this vendor patch cycle is broader than one product.
CVSS 8.8 HIGH: solarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability. EPSS 0.5% (45th percentile).
1 source covering this story
SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE
SolarWinds patched an ARM flaw caused by a hard-coded static key that could enable unauthenticated remote code execution.
Part of the PlainSec briefing for 2026-09-20