SolarWinds Access Rights Manager hard-coded key → unauth RCE CVE-2026-28326 (CVSS 8.8); fix 2026.2.1
SolarWinds Trust Center advisory CVE-2026-28326 (first published 17 September 2026) documents an unauthenticated remote code execution flaw in Access Rights Manager (ARM) stemming from a hard-coded static key. CVSS 3.1 8.8 High (AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H — adjacent network). Affected: ARM 2026.2 and all previous versions. Fixed: ARM 2026.2.1. Credit: Kai Huang (Armadin). SolarWinds makes no mention of in-the-wild exploitation. The Hacker News (19 Sep) also notes earlier July WHD SAML bypass CVE-2026-28323 (9.8; fix WHD 2026.2.1) and Serv-U fixes — those are separate advisories; this card is ARM only. Primary: SolarWinds Trust Center; secondary: THN / ARM 2026.2.1 release notes.
- Product
- SolarWinds Access Rights Manager (ARM)
- Versions
- ARM 2026.2 and all previous versions
- CVSS
- (CVSS 3.1 High; SolarWinds)
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - Exploited in Australia?
- unknown
- Patch to
- Upgrade SolarWinds Access Rights Manager to 2026.2.1 (or later fixed release). Restrict ARM management interfaces to trusted admin networks — CVSS attack vector is adjacent (AV:A).
Primary: SolarWinds — CVE-2026-28326 ARM unauthenticated RCE (17 Sep 2026) · Vendor: SolarWinds Trust Center — Access Rights Manager advisory · CVE: CVE-2026-28326, CVE-2026-28323 · The Hacker News — SolarWinds ARM hard-coded key RCE (19 Sep 2026)
