InfoSec News Nuggets – 09/22/2026
Brief
SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE
SolarWinds has shipped security updates for Access Rights Manager after discovering a hard-coded static cryptographic key that could let an attacker execute code on a managed host without authentication. Tracked as CVE-2026-28326 with a CVSS score of 8. 8, the flaw affects all ARM versions 2026. 2 and earlier and was privately reported by a security researcher rather than found through active exploitation.
Administrators are urged to upgrade to ARM 2026.
- 1, which also resolves a batch of other recently disclosed flaws in the company’s Web Help Desk and Serv-U products.
