#7
The Hacker News
general
September 19, 2026 at 09:31 UTC
SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE
By [email protected] (The Hacker News)
AI Summary
SolarWinds patched CVE-2026-28326 (CVSS 8.8), a hard-coded cryptographic key vulnerability in Access Rights Manager (ARM) affecting all versions through 2026.2 that enables unauthenticated remote code execution. ARM is used for privileged access governance, making unauthenticated RCE in this product a high-value target for attackers seeking lateral movement into sensitive identity infrastructure.
Relevance score: 82.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →