SolarWinds has issued important security patches to mitigate a significant vulnerability in its Access Rights Manager (ARM) software. This critical flaw, identified as CVE-2026-28326, could potentially allow unauthorized remote code execution if exploited. The vulnerability is rated 8.8 on the Common Vulnerability Scoring System (CVSS), indicating its high severity.
Details of the Vulnerability
The discovered issue affects all versions of Access Rights Manager prior to the 2026.2.1 update. The flaw arises from a hard-coded static key, which could be manipulated to gain unauthorized access. This vulnerability was first reported by Kai Huang, a security researcher from Armadin, and SolarWinds acknowledged his contribution in their advisory dated September 17, 2026. Fortunately, there have been no reports of this vulnerability being exploited in the wild.
Previous Security Concerns
This update follows SolarWinds’ recent efforts to enhance security across its product line. Just two months ago, SolarWinds addressed a critical flaw in its Web Help Desk (WHD) known as CVE-2026-28323, with a CVSS score of 9.8. This particular issue could have led to a bypass of SAML authentication when using the SAML 2.0 method. Additionally, another vulnerability in WHD, identified as CVE-2026-28299, was resolved, which previously risked causing server crashes due to inadequate memory handling.
Broader Security Updates
In addition to these patches, SolarWinds has tackled various vulnerabilities affecting its Serv-U product. This includes a series of flaws ranging from CVE-2026-28302 to CVE-2026-28323, which could potentially lead to privilege escalation, unauthorized remote code execution, and the creation of administrator accounts. The company has been proactive in ensuring these issues are addressed to safeguard its users.
These security measures underline SolarWinds’ commitment to maintaining the integrity and reliability of its software products, ensuring that users are protected from potential cyber threats.
By staying vigilant and promptly releasing updates, SolarWinds continues to demonstrate its dedication to cybersecurity and user safety. Users are urged to apply these updates immediately to protect their systems against potential exploits.
