Patch released SolarWinds Access Rights Manager rce SolarWinds
SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE
CVE Tools coverage
SolarWinds has fixed CVE-2026-28326, an 8.8-severity hard-coded static key issue in Access Rights Manager (ARM) that could allow unauthenticated remote code execution. All versions of Access Rights Manager 2026.2 and prior are affected; the company addressed the flaw in ARM 2026.2.1 and has not reported active exploitation. SolarWinds also recently resolved Web Help Desk flaws CVE-2026-28323 and CVE-2026-28299 in WHD 2026.2.1, and released Serv-U fixes for CVE-2026-28302, from CVE-2026-28304 through CVE-2026-28317, CVE-2026-28321, CVE-2026-28323.