Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
SolarWinds Fixes Critical ARM Security Flaw

SolarWinds Fixes Critical ARM Security Flaw

Posted on September 19, 2026 By CWS

SolarWinds has issued important security patches to mitigate a significant vulnerability in its Access Rights Manager (ARM) software. This critical flaw, identified as CVE-2026-28326, could potentially allow unauthorized remote code execution if exploited. The vulnerability is rated 8.8 on the Common Vulnerability Scoring System (CVSS), indicating its high severity.

Details of the Vulnerability

The discovered issue affects all versions of Access Rights Manager prior to the 2026.2.1 update. The flaw arises from a hard-coded static key, which could be manipulated to gain unauthorized access. This vulnerability was first reported by Kai Huang, a security researcher from Armadin, and SolarWinds acknowledged his contribution in their advisory dated September 17, 2026. Fortunately, there have been no reports of this vulnerability being exploited in the wild.

Previous Security Concerns

This update follows SolarWinds’ recent efforts to enhance security across its product line. Just two months ago, SolarWinds addressed a critical flaw in its Web Help Desk (WHD) known as CVE-2026-28323, with a CVSS score of 9.8. This particular issue could have led to a bypass of SAML authentication when using the SAML 2.0 method. Additionally, another vulnerability in WHD, identified as CVE-2026-28299, was resolved, which previously risked causing server crashes due to inadequate memory handling.

Broader Security Updates

In addition to these patches, SolarWinds has tackled various vulnerabilities affecting its Serv-U product. This includes a series of flaws ranging from CVE-2026-28302 to CVE-2026-28323, which could potentially lead to privilege escalation, unauthorized remote code execution, and the creation of administrator accounts. The company has been proactive in ensuring these issues are addressed to safeguard its users.

These security measures underline SolarWinds’ commitment to maintaining the integrity and reliability of its software products, ensuring that users are protected from potential cyber threats.

By staying vigilant and promptly releasing updates, SolarWinds continues to demonstrate its dedication to cybersecurity and user safety. Users are urged to apply these updates immediately to protect their systems against potential exploits.

The Hacker News Tags:Arm, CVE-2026-28326, Cybersecurity, identity security, Patch, remote code execution, security update, software update, SolarWinds, Vulnerability

Post navigation

Previous Post: Hackers Exploit TanStack to Steal GitHub Repositories
Next Post: Identity Visibility: Key to Secure IAM by 2026

Related Posts

eScan Antivirus Update Servers Compromised to Deliver Multi-Stage Malware eScan Antivirus Update Servers Compromised to Deliver Multi-Stage Malware The Hacker News
VS Code Forks Recommend Missing Extensions, Creating Supply Chain Risk in Open VSX VS Code Forks Recommend Missing Extensions, Creating Supply Chain Risk in Open VSX The Hacker News
Malicious PyPI, npm, and Ruby Packages Exposed in Ongoing Open-Source Supply Chain Attacks Malicious PyPI, npm, and Ruby Packages Exposed in Ongoing Open-Source Supply Chain Attacks The Hacker News
OpenAI Discloses Six AI Model Failures and New Framework OpenAI Discloses Six AI Model Failures and New Framework The Hacker News
Fake Open-Source Tool Sites Exploit Google Rankings for Malware Fake Open-Source Tool Sites Exploit Google Rankings for Malware The Hacker News
China-Linked JadeProx Unveils TriBack Loader in Cyber Attacks China-Linked JadeProx Unveils TriBack Loader in Cyber Attacks The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • TigerByte Cyber Launches with $3M Funding to Enhance Security
  • Identity Visibility: Key to Secure IAM by 2026
  • SolarWinds Fixes Critical ARM Security Flaw
  • Hackers Exploit TanStack to Steal GitHub Repositories
  • Researchers Exploit OpenAI Accounts via Security Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • TigerByte Cyber Launches with $3M Funding to Enhance Security
  • Identity Visibility: Key to Secure IAM by 2026
  • SolarWinds Fixes Critical ARM Security Flaw
  • Hackers Exploit TanStack to Steal GitHub Repositories
  • Researchers Exploit OpenAI Accounts via Security Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark