519/69 Monday, September 21, 2026
SolarWinds has released a security update to address CVE-2026-28326 in its Access Rights Manager (ARM) product. The vulnerability has a CVSS score of 8.8 and could allow an unauthenticated attacker to execute commands on affected systems. The flaw affects Access Rights Manager version 2026.2 and earlier, and SolarWinds has already released a fix. At this time, there is no confirmed information indicating that the vulnerability has been exploited in real-world attacks.
The vulnerability stems from the use of a hard-coded static key within Access Rights Manager. This could allow an attacker to abuse the embedded key in the product to bypass security restrictions and achieve command execution without authentication. However, SolarWinds has not disclosed additional technical details about the attack process or the specific conditions required for exploitation. The vulnerability was discovered and reported by researchers from Armadin.
Administrators using SolarWinds Access Rights Manager should check their deployed versions and update to ARM 2026.2.1 or later as soon as possible, as this version includes the fix for CVE-2026-28326. For systems running older versions, administrators should review SolarWinds’ upgrade requirements and procedures before proceeding to prevent issues that may occur during the update process.
Source: https://thehackernews.com/2026/09/solarwinds-patches-arm-hard-coded-key.html
