SolarWinds has released a security update addressing CVE-2026-28326, a high-severity vulnerability in Access Rights Manager (ARM) that could allow unauthenticated attackers to execute arbitrary code remotely.
The vulnerability carries a CVSS score of 8.8 and stems from a hard-coded static key. It affects ARM version 2026.2 and earlier and has been fixed in version 2026.2.1.
Why is this vulnerability concerning?
Access Rights Manager is designed to manage and audit access permissions across enterprise environments. A successful compromise of such a system could potentially expose sensitive access configurations, credentials and connected resources, depending on the privileges available to the compromised application.
The vulnerability also highlights a fundamental security weakness: embedding static security keys directly into software can undermine authentication and other security controls when those keys become accessible to attackers.
Although there is currently no confirmed evidence of active exploitation, organisations should prioritise remediation because the vulnerability can potentially be exploited without authentication.
Recommended security actions:
- Upgrade SolarWinds ARM to version 2026.2.1 or later.
- Restrict ARM access to authorised administrators and trusted management networks.
- Avoid exposing management interfaces directly to the internet.
- Monitor unusual authentication activity, unexpected processes and suspicious outbound connections originating from ARM servers.
- Review systems for possible compromise if they were previously exposed.
- Apply least-privilege permissions to ARM service accounts and connected resources.
The key takeaway: Security products and access management platforms must themselves be protected against vulnerabilities that undermine their authentication and execution boundaries. Hard-coded secrets create avoidable risks, and a compromise of privileged management software can have consequences far beyond the affected application.
Organisations should combine timely patching, strict access controls, secure credential management and continuous monitoring to reduce the risk of exploitation.

SolarWinds has released security updates to address a high-severity flaw in Access Rights Manager (ARM) that, if successfully exploited, could lead to an unauthenticated remote code execution vulnerability. The vulnerability, tracked as CVE-2026-28326, is rated 8.8 out of 10.0 on the CVSS scoring system. The issue affects all versions of Access Rights Manager 2026.2 and prior. "SolarWinds
Source: SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE via The Hacker News — published 19 Sep 2026.
Was this article helpful?
Your feedback helps us improve the knowledge base.