SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE

SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE
SolarWinds has patched a high-severity vulnerability in Access Rights Manager, tracked as CVE-2026-28326, that could allow unauthenticated remote code execution due to a hard-coded static key. The company also released fixes for serious flaws in Web Help Desk and multiple Serv-U issues, including risks of privilege escalation, remote code execution, and administrator account creation. #SolarWinds #AccessRightsManager #CVE-2026-28326 #WebHelpDesk #ServU

Keypoints

  • SolarWinds fixed a high-severity flaw in Access Rights Manager.
  • CVE-2026-28326 could enable unauthenticated remote code execution.
  • The vulnerability affects all versions of Access Rights Manager 2026.2 and earlier.
  • SolarWinds patched the issue in ARM 2026.2.1.
  • The company also released updates for Web Help Desk and Serv-U vulnerabilities.

Read More: https://thehackernews.com/2026/09/solarwinds-patches-arm-hard-coded-key.html