Skip to content
TodayPrism
Updated 1h agoTech & Cyber

SolarWinds Patches Access Rights Manager Flaw Enabling Unauthenticated RCE

Headline by Prism · from 1 report

SolarWinds patched a high-severity hard-coded credential vulnerability in its Access Rights Manager software that could allow remote code execution.

1 outlet · 1 report · EnglishOne source so far

The record

Written from the 1 report below. Nothing here is unsourced.

  • SolarWinds has released a security patch for its Access Rights Manager software to fix a high-severity vulnerability identified as CVE-2026-28326.
  • The flaw, caused by a hard-coded static key, could potentially allow an unauthenticated attacker to execute code remotely.
  • The company reported that the issue affects all versions up to 2026.2 and has been resolved in version 2026.2.1.

Who said what2

Only words found exactly in the article are shown, attributed and linked to the line they came from.

SolarWinds

2 quotes · 1 outlet

  • SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability
    [1]The Hacker News3h agoOpen at the quote ↗
    In the article

    remote code execution vulnerability. The vulnerability, tracked as CVE-2026-28326, is rated 8.8 out of 10.0 on the CVSS scoring system. The issue affects all versions of Access Rights Manager 2026.2 and prior. " SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability ," SolarWinds said in an advisory released on September 17, 2026. "The issue stems from a hard-coded static key." The company credited Armadin security researcher Kai Huang with discovering and reporting the flaw, which

  • The issue stems from a hard-coded static key.
    [1]The Hacker News3h agoOpen at the quote ↗
    In the article

    Rights Manager 2026.2 and prior. "SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability," SolarWinds said in an advisory released on September 17, 2026. " The issue stems from a hard-coded static key. " The company credited Armadin security researcher Kai Huang with discovering and reporting the flaw, which has been patched in ARM 2026.2.1. SolarWinds makes no mention of the vulnerability being exploited in the wild.

Coverage1

1 report
English national1

All filed from India

Named India · Access Rights Manager · Serv-U · Web Help Desk · Armadin · Kai Huang · Solarwinds

Ask this story

Answers cite the reports above, or say they can't.

← Today’s record

SolarWinds Patches Access Rights Manager Flaw Enabling Unauthenticated RCE | Prism