Back to News
Cybersecurity

SolarWinds Addresses Critical RCE Vulnerability in Access Rights Manager

SolarWinds has issued critical patches for a high-severity flaw in Access Rights Manager that poses risks of unauthenticated remote code execution.

SolarWinds has announced the release of security updates for its Access Rights Manager (ARM) following the discovery of a significant vulnerability, designated CVE-2026-28326, which carries a CVSS score of 8.8. This flaw allows for unauthenticated remote code execution, jeopardizing the security of all versions of ARM 2026.2 and earlier. The potential exploitation of this vulnerability underscores a pressing need for organizations using these versions to implement the patches promptly to safeguard their systems against unauthorized access and control.

For businesses, the implications of this vulnerability are considerable, as it highlights the critical importance of maintaining up-to-date security protocols and software versions. Organizations should prioritize the timely application of security patches, especially for widely-used tools like SolarWinds, which play a pivotal role in IT management and security. This incident serves as a reminder of the ever-evolving threat landscape in cybersecurity and emphasizes the necessity for proactive measures to protect sensitive data and infrastructure in an era where vulnerabilities can be easily exploited by malicious actors.

---

*Originally reported by [The Hacker News](https://thehackernews.com/2026/09/solarwinds-patches-arm-hard-coded-key.html)*