ZeroHour
The Hacker Newspublished ()ingested [email protected] (The Hacker News)

SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE

AI summary · glm-5.3-flash

SolarWinds patched CVE-2026-28326 (CVSS 8.8), a hard-coded-key flaw enabling unauthenticated remote code execution in Access Rights Manager 2026.2 and prior.

SolarWinds released ARM 2026.2.1 on September 17, 2026 to fix CVE-2026-28326, an unauthenticated remote code execution flaw in Access Rights Manager caused by a hard-coded static key, reported by Armadin researcher Kai Huang. The company stated there is no evidence of exploitation in the wild. The same cycle resolved Web Help Desk issues CVE-2026-28323 (CVSS 9.8, SAML authentication bypass) and CVE-2026-28299 (CVSS 8.2, denial-of-service), plus 16 Serv-U flaws enabling privilege escalation, RCE, and administrator account creation.

  • CVE-2026-28326 (CVSS 8.8) stems from a hard-coded static key allowing unauthenticated RCE in ARM 2026.2 and prior.
  • Fixed in Access Rights Manager 2026.2.1; credited to Armadin researcher Kai Huang; no in-the-wild exploitation reported.
  • SolarWinds also fixed WHD SAML authentication bypass CVE-2026-28323 (CVSS 9.8) and DoS flaw CVE-2026-28299 (CVSS 8.2).
  • Sixteen Serv-U flaws enabling privilege escalation, remote code execution, and administrator account creation were also patched.

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-28299
SolarWinds Web Help Desk is found to be affected by a denial-of-service vulnerability, which when exploited, could cause the Web Help Desk server to crash due t

SolarWinds Web Help Desk is found to be affected by a denial-of-service vulnerability, which when exploited, could cause the Web Help Desk server to crash due to insufficient memory.

NVD description · AI analysis pending
7.5<1%
  • solarwinds web help desk
CVE-2026-28316
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation to a system administrator with t

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation to a system administrator with the ability to execute commands as the root user. This issue requires a domain account with administrator access. The impact is lower in Windows deployments.

NVD description · AI analysis pending
9.1
group max
2%
  • solarwinds serv-u
CVE-2026-28311

NVD description · AI analysis pending
CVE-2026-28323
SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability.

SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2.0 authentication method to be enabled.

NVD description · AI analysis pending
9.8<1%
  • solarwinds web help desk
CVE-2026-28326
Unauthenticated RCE in SolarWinds Access Rights Manager via hardcoded static key

SolarWinds Access Rights Manager (ARM) contains an unauthenticated remote code execution flaw caused by a hardcoded static cryptographic key (CWE-321). An attacker who can reach the ARM service from an adjacent network, as reflected in the CVSS attack vector, can abuse the static key to bypass authentication and execute code without any user interaction or credentials. Successful exploitation yields high-impact code execution on the ARM server, which typically holds privileged Active Directory and service credentials, creating significant lateral-movement risk. Organizations running ARM on-premises, most commonly mid-size and large enterprises managing file-server and AD permissions, are affected. No public proof-of-concept is known, the issue is not on the CISA KEV list, and there are no confirmed reports of exploitation in the wild.

Do: Upgrade SolarWinds Access Rights Manager to the fixed release identified in the SolarWinds security advisory (specific fixed version not stated in the available data). Until patched, restrict network access to the ARM server to dedicated management segments or VPN, since exploitation requires adjacent network access, and monitor ARM hosts for unexpected processes and outbound connections. Because ARM stores privileged directory credentials, treat any suspected compromise as potential domain compromise and rotate the credentials it manages.

8.8
  • SolarWinds Access Rights Manager
moderate≈10,000–100,000 on-premises installations worldwide (order-of-magnitude estimate)
Full article262 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananSep 19, 2026Vulnerability / Identity Security

SolarWinds has released security updates to address a high-severity flaw in Access Rights Manager (ARM) that, if successfully exploited, could lead to an unauthenticated remote code execution vulnerability.

The vulnerability, tracked as CVE-2026-28326, is rated 8.8 out of 10.0 on the CVSS scoring system. The issue affects all versions of Access Rights Manager 2026.2 and prior.

"SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability," SolarWinds said in an advisory released on September 17, 2026. "The issue stems from a hard-coded static key."

The company credited Armadin security researcher Kai Huang with discovering and reporting the flaw, which has been patched in ARM 2026.2.1. SolarWinds makes no mention of the vulnerability being exploited in the wild.

The development comes nearly two months after the company shipped fixes for a critical flaw impacting Web Help Desk (WHD) (CVE-2026-28323, CVSS score: 9.8) that could result in a SAML authentication bypass when the SAML 2.0 authentication method is enabled.

Another vulnerability relates to a denial-of-service (DoS) vulnerability (CVE-2026-28299, CVSS score: 8.2) that could cause the Web Help Desk server to crash due to insufficient memory. Both issues have been resolved in WHD 2026.2.1.

SolarWinds has also released fixes for 16 flaws impacting Serv-U (CVE-2026-28302, from CVE-2026-28304 through CVE-2026-28317, CVE-2026-28321, CVE-2026-28323) that could lead to privilege escalation, remote code execution, and the creation of administrator accounts.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2026/09/solarwinds-patches-arm-hard-coded-key.html