SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE
ID: 51bfa872-0eb0-55dd-9d4e-339e36c6eafd
STIX ID: report--51bfa872-0eb0-55dd-9d4e-339e36c6eafd
Feed Name: The Hacker News
Threat Score
**SolarWinds released patches for multiple high-severity vulnerabilities**, most notably an unauthenticated remote code execution in Access Rights Manager (CVE-2026-28326, CVSS 8.8) caused by a hard-coded static key and fixed in ARM 2026.2.1; the advisory also references critical Web Help Desk and Serv-U flaws (including SAML bypass and DoS issues) resolved in recent updates, and SolarWinds reports no known exploitation in the wild.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
