SolarWinds has released security updates to fix a high-severity vulnerability in its Access Rights Manager (ARM) software that could allow an unauthenticated attacker to execute arbitrary code remotely on affected systems.

Tracked as CVE-2026-28326, the vulnerability carries a CVSS score of 8.8 out of 10 and affects all versions of Access Rights Manager 2026.2 and earlier. According to SolarWinds, the issue is caused by a hard-coded static key in the software.

“SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability,” the company said in a security advisory published on September 17, 2026.

Armadin security researcher Kai Huang discovered and reported the vulnerability. SolarWinds has addressed the issue in Access Rights Manager 2026.2.1. The company has not reported any evidence that the vulnerability has been exploited in real-world attacks.

The latest update follows several other security fixes SolarWinds released in recent months. Nearly two months ago, the company patched a critical vulnerability in Web Help Desk, tracked as CVE-2026-28323, which has a CVSS score of 9.8 and could allow a SAML authentication bypass when SAML 2.0 authentication is enabled.

SolarWinds also fixed a separate denial-of-service vulnerability in Web Help Desk, tracked as CVE-2026-28299 and rated 8.2. The flaw could cause a Web Help Desk server to crash because of insufficient memory. Both vulnerabilities have been addressed in Web Help Desk 2026.2.1.

In addition, SolarWinds has released fixes for 16 vulnerabilities affecting its Serv-U software. The flaws, tracked under CVE-2026-28302, CVE-2026-28304 through CVE-2026-28317, CVE-2026-28321 and CVE-2026-28323, could potentially lead to privilege escalation, remote code execution and the creation of unauthorized administrator accounts.


Buy ExpressVPN with PayPal or Credit Card
READ
How to Protect Yourself From Deepfake Scams and Fake Video Calls

Organizations using SolarWinds Access Rights Manager should update to version 2026.2.1 or the appropriate patched release as soon as possible to address the newly disclosed vulnerability.

Advertisement