logo

SolarWinds Patches 8 Critical Flaws in Access Rights Manager Software

ID: e777a664-c184-5369-91df-633af23fb7f2

STIX ID: report--e777a664-c184-5369-91df-633af23fb7f2

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2024-07-19

Date Updated: 2026-05-08

Author: [email protected] (The Hacker News)

...
...

SolarWinds disclosed and patched 13 vulnerabilities in its Access Rights Manager (ARM), eight of which are rated Critical (CVSS 9.6) and include remote code execution and directory traversal flaws (multiple CVEs). Successful exploitation could permit file disclosure or deletion and execution of arbitrary code with elevated privileges; fixes were released in ARM 2024.3 on July 17, 2024, following responsible disclosure via Trend Micro ZDI. The report also references related CISA action on a separate Serv-U path traversal KEV entry and recalls SolarWinds' 2020 supply-chain compromise for context.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.