Skip to content
feed: live
>_0dayNews
CVE Record
[ HIGH ]CVE-2026-28326

SolarWinds ARM hard-coded key enables unauthenticated RCE

Hard-coded static key in SolarWinds Access Rights Manager through 2026.2 lets unauthenticated attackers execute arbitrary code remotely. Fixed in ARM 2026.2.1.

cat cve-2026-28326.json
Vendor
SolarWinds
Product
Access Rights Manager (ARM)
CVSS
8.8
EPSS (exploit probability)
0.5%
Status
patched
Published

A static key hard-coded into SolarWinds Access Rights Manager (ARM) through version 2026.2 lets an unauthenticated attacker bypass authentication and execute arbitrary code on the server. No credentials required to trigger the flaw.

Fixed in ARM 2026.2.1, released September 17, 2026. SolarWinds reports no evidence of exploitation in the wild as of the advisory date. Researcher Kai Huang of Armadin reported the vulnerability.

Upgrade to ARM 2026.2.1. Full version details and upgrade steps are in the SolarWinds advisory. If patching is not immediately possible, restrict network access to the ARM management interface to trusted hosts.