SolarWinds Patches Critical Hard-Coded Key Flaw in Access Rights Manager
SolarWinds has released a patch for a critical vulnerability (CVE-2026-28326) in its Access Rights Manager software, which could allow unauthenticated attackers to execute remote code.

SolarWinds has addressed a significant security vulnerability in its Access Rights Manager (ARM) software, releasing an update to patch a flaw that could enable unauthenticated remote code execution. The vulnerability, identified as CVE-2026-28326, carries a CVSS score of 8.8 out of 10.0, indicating a high severity.
The core of the issue lies in a hard-coded static key within the ARM software. This hard-coded key, when exploited, allows attackers who have not authenticated to the system to gain control and execute arbitrary code on the affected servers. This poses a substantial risk to organizations relying on SolarWinds ARM for managing access rights.
The vulnerability impacts all versions of Access Rights Manager up to and including version 2026.2. SolarWinds has released version 2026.2.1 to rectify this security defect. The company has stated that it is not aware of any instances where this vulnerability has been exploited in the wild.
This patch comes shortly after SolarWinds issued fixes for other critical vulnerabilities. In August 2026, the company released updates for its Web Help Desk (WHD) product, addressing a critical flaw (CVE-2026-28323) that could lead to a SAML authentication bypass and a denial-of-service vulnerability (CVE-2026-28299) that could cause server crashes.
Furthermore, SolarWinds also released patches for a suite of 16 vulnerabilities affecting its Serv-U software. These flaws, ranging from CVE-2026-28302 to CVE-2026-28323, could potentially lead to privilege escalation, remote code execution, and the unauthorized creation of administrator accounts.
The discovery and reporting of the CVE-2026-28326 vulnerability in Access Rights Manager are credited to Kai Huang, a security researcher from Armadin. The prompt patching by SolarWinds underscores the ongoing efforts by vendors to secure their products against emerging threats.
Organizations utilizing SolarWinds Access Rights Manager are strongly advised to update to version 2026.2.1 as soon as possible to mitigate the risk of exploitation. The presence of hard-coded keys in software continues to be a recurring security concern, highlighting the importance of secure coding practices and thorough security audits.
This incident serves as a reminder for all software vendors to rigorously vet their code for such hard-coded secrets and for users to promptly apply security updates to protect their infrastructure from potential compromise.