SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE
Brief
SolarWinds has released security updates to address a high-severity flaw in Access Rights Manager (ARM) that, if successfully exploited, could lead to an unauthenticated remote code execution vulnerability.
The vulnerability, tracked as CVE-2026-28326, is rated 8. 8 out of 10. 0 on the CVSS scoring system. The issue affects all versions of Access Rights Manager 2026. 2 and prior.
