SolarWinds has released security updates for Access Rights Manager (ARM) to fix a newly disclosed vulnerability, tracked as CVE-2026-28326, that could allow unauthenticated remote code execution on affected systems.[1][3][7]
The flaw arises from the use of a hard-coded static cryptographic key in ARM, a pattern categorized as CWE-321, which can let an attacker bypass normal authentication and execute arbitrary code once they gain access to the network segment where the product is deployed.[1][4][5]
Public CVE entries describe CVE-2026-28326 as a high-severity issue with a CVSS v3.1 base score of 8.8, using the vector AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, reflecting the combination of low attack complexity, no required privileges, and full impact on confidentiality, integrity and availability.[1][2][4]
Vendor-linked data indicates that SolarWinds Access Rights Manager version 2026.2 and all previous releases are affected, with third-party trackers pointing to a fixed build documented in the ARM 2026.2.1 release notes and a dedicated trust-center advisory for CVE-2026-28326.ARM 2026.2.1 release notesSolarWinds advisory[4][5][6]
So far, public vulnerability trackers and coverage—including entries from Tenable, CVEFeed and other CVE databases—do not reference confirmed exploitation in the wild, but the network-adjacent attack vector and unauthenticated nature of the bug mean that exploitation attempts are likely as details circulate.[2][6][11]
Guidance from CVE-focused services stresses the need to update SolarWinds ARM to the latest fixed release, review and remove hard-coded keys where possible, harden access controls around ARM deployments, and ensure timely application of vendor security patches to reduce exposure to CVE-2026-28326.[5][6]
Organizations using SolarWinds Access Rights Manager should prioritize patching, verify that their environment is running a remediated version, and monitor for suspicious lateral movement or privilege-management activity as attackers increasingly target identity and access-management tools for high-impact compromises.[3][7]
References
- CVE Record: CVE-2026-28326
- CVE-2026-28326
- «Hacker News» 🗞️🦾 IT BOLTWISE®
- CVE-2026-28326: Access Rights Manager Vulnerability … – Strix
- FKIE_CVE-2026-28326
- CVE-2026-28326 – SolarWinds Access Rights Manager Unauthenticated Remote Code Execution Vulnerability
- CVE-2026-28326: SolarWinds ARM Unauth RCE Key
- Common Vulnerabilities and Exposures (CVE) – HackTesting