SolarWinds security advisory (AV26-941)
Canadian Cyber Centre alerts on unauthenticated RCE vulnerability CVE-2026-28326 in SolarWinds Access Rights Manager before 2026.2.
The Canadian Centre for Cyber Security issued advisory AV26-941 for an unauthenticated remote code execution vulnerability, CVE-2026-28326, affecting SolarWinds Access Rights Manager versions prior to 2026.2. Administrators are encouraged to review the provided links and apply updates as they become available.
- CVE-2026-28326 enables unauthenticated remote code execution
- Affects SolarWinds Access Rights Manager prior to 2026.2
- Advisory AV26-941 dated September 18, 2026 urges prompt patching
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-28326 | Unauthenticated RCE in SolarWinds Access Rights Manager via hardcoded static key SolarWinds Access Rights Manager (ARM) contains an unauthenticated remote code execution flaw caused by a hardcoded static cryptographic key (CWE-321). An attacker who can reach the ARM service from an adjacent network, as reflected in the CVSS attack vector, can abuse the static key to bypass authentication and execute code without any user interaction or credentials. Successful exploitation yields high-impact code execution on the ARM server, which typically holds privileged Active Directory and service credentials, creating significant lateral-movement risk. Organizations running ARM on-premises, most commonly mid-size and large enterprises managing file-server and AD permissions, are affected. No public proof-of-concept is known, the issue is not on the CISA KEV list, and there are no confirmed reports of exploitation in the wild. Do: Upgrade SolarWinds Access Rights Manager to the fixed release identified in the SolarWinds security advisory (specific fixed version not stated in the available data). Until patched, restrict network access to the ARM server to dedicated management segments or VPN, since exploitation requires adjacent network access, and monitor ARM hosts for unexpected processes and outbound connections. Because ARM stores privileged directory credentials, treat any suspected compromise as potential domain compromise and rotate the credentials it manages. | 8.8 | — |
| moderate≈10,000–100,000 on-premises installations worldwide (order-of-magnitude estimate) |
Full article61 words · extracted from cyber.gc.ca · click to collapse
Serial number: AV26-941
Date: September 18, 2026
As of September 17, 2026, SolarWinds is affected by a vulnerability in the following product:
- SolarWinds Access Rights Manager
- Prior to 2026.2
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/solarwinds-security-advisory-av26-941