Access Rights Manager exists to tell you who can touch what. A hard-coded static key in every install turns that trust map into an unauthenticated remote code execution problem — and the fix is a same-week upgrade to 2026.2.1.
What happened
On September 17, 2026, SolarWinds published an advisory for CVE-2026-28326: Access Rights Manager is affected by an unauthenticated remote code execution vulnerability stemming from a hard-coded static cryptographic key (CWE-321). The issue affects ARM 2026.2 and all previous versions. Fixed software: ARM 2026.2.1. CVSS 3.1 8.8 (AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). Credit: Kai Huang, Armadin.
SolarWinds reports no evidence of exploitation in the wild as of the advisory. The advisory does not detail which protocol object the key protects — operators should treat “unauthenticated RCE + static key” as enough to prioritize without waiting for a public write-up.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
Why it matters
A hard-coded key extracted once works on the next server, and the one after that. ARM’s job is identity and entitlement visibility across directories and file shares — landing there is an unusually efficient place for an attacker to learn (and then abuse) who can reach what. Adjacent-network unauthenticated RCE on that class of product is a Monday change-window item, not a quarterly patch bag.
What to do first
- Inventory every Access Rights Manager instance (prod, lab, MSP-managed).
- Upgrade all builds ≤2026.2 to 2026.2.1.
- Pull ARM management interfaces off broad LAN/WAN exposure; restrict to admin jump hosts / VPN.
- After upgrade: review ARM authentication logs and host EDR for pre-patch anomalous sessions or process trees.
- Rotate any secrets ARM integrates with (directory service accounts, service principals) if compromise is plausible.
- Review SolarWinds’ secure-deployment guidance for ARM hardening beyond the version bump.
Details
- CVE: CVE-2026-28326
- Product: SolarWinds Access Rights Manager
- Affected: 2026.2 and all previous versions
- Fixed: 2026.2.1
- CVSS: 8.8 High
- CWE: CWE-321 Use of Hard-coded Cryptographic Key
- Exploitation: None known per vendor (as of advisory)
- First published: 2026-09-17
Hunt / verify
- Confirm installed ARM version string is 2026.2.1+.
- Baseline ARM service accounts and outbound integrations; watch for new local admins or unexpected agents post-advisory.
- Network: unusual connections to ARM ports from non-admin subnets.
Sources
- https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28326
- https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2026-2-1_release_notes.htm
- https://nvd.nist.gov/vuln/detail/CVE-2026-28326
- https://www.cve.org/CVERecord?id=CVE-2026-28326
- https://thehackernews.com/ (Sep 19, 2026 coverage of ARM hard-coded key RCE)
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.