importantSYS.SOURCE: The Hacker News• 2026-09-19T15:01:17+05:30
SolarWinds Addresses Critical ARM Vulnerability (CVE-2026-28326) with Unauthenticated RCE Risk
SolarWinds released security updates to address a high-severity vulnerability (CVE-2026-28326) in Access Rights Manager, which could enable unauthenticated remote code execution due to a hard-coded static key. The flaw was patched in ARM 2026.2.1, with no evidence of exploitation in the wild.
SolarWinds has released security updates to address a high-severity flaw in Access Rights Manager (ARM) that, if successfully exploited, could lead to an unauthenticated remote code execution vulnerability.
The vulnerability, tracked as CVE-2026-28326, is rated 8.8 out of 10.0 on the CVSS scoring system. The issue affects all versions of Access Rights Manager 2026.2 and prior.
"SolarWinds
*** END OF TRANSMISSION ***