logo

SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE

ID: aa97e937-565f-5727-bf99-504be0162f08

STIX ID: report--aa97e937-565f-5727-bf99-504be0162f08

Feed Name: CosmicBytez Labs

Threat Score
70/100

Date Published: 2026-09-19

Date Updated: 2026-09-19

...
...

SolarWinds released a patch for CVE-2026-28326 — a high-severity (CVSS 8.8) unauthenticated RCE in Access Rights Manager caused by a hard-coded static cryptographic key. The flaw affects ARM versions 2026.2 and earlier and is fixed in 2026.2.1; exploitation requires adjacent-network access. Administrators are advised to upgrade immediately, restrict network access to the ARM host, and review logs; SolarWinds reported no evidence of in-the-wild exploitation at publication.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.