SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE

Summary

SolarWinds has released security updates to fix a critical vulnerability in its Access Rights Manager (ARM) software. The flaw, CVE-2026-28326, allows for unauthenticated remote code execution and has a high severity rating.

IFF Assessment

FOE

This vulnerability allows for unauthenticated remote code execution, which is a serious threat that defenders must mitigate.

Severity

8.8 High

Defender Context

This vulnerability in SolarWinds ARM presents a significant risk for organizations using the software, as it enables unauthenticated remote code execution. Defenders should prioritize patching this vulnerability immediately to prevent potential exploitation by threat actors.

Read Full Story →