SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE
SolarWinds patched CVE-2026-28326 (CVSS 8.8), a hard-coded-key flaw enabling unauthenticated remote code execution in Access Rights Manager 2026.2 and prior.
SolarWinds released ARM 2026.2.1 on September 17, 2026 to fix CVE-2026-28326, an unauthenticated remote code execution flaw in Access Rights Manager caused by a hard-coded static key, reported by Armadin researcher Kai Huang. The company stated there is no evidence of exploitation in the wild. The same cycle resolved Web Help Desk issues CVE-2026-28323 (CVSS 9.8, SAML authentication bypass) and CVE-2026-28299 (CVSS 8.2, denial-of-service), plus 16 Serv-U flaws enabling privilege escalation, RCE, and administrator account creation.