SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE
ID: aa97e937-565f-5727-bf99-504be0162f08
STIX ID: report--aa97e937-565f-5727-bf99-504be0162f08
Feed Name: CosmicBytez Labs
Threat Score
SolarWinds released a patch for CVE-2026-28326 — a high-severity (CVSS 8.8) unauthenticated RCE in Access Rights Manager caused by a hard-coded static cryptographic key. The flaw affects ARM versions 2026.2 and earlier and is fixed in 2026.2.1; exploitation requires adjacent-network access. Administrators are advised to upgrade immediately, restrict network access to the ARM host, and review logs; SolarWinds reported no evidence of in-the-wild exploitation at publication.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
