SolarWinds Patches High-Severity RCE Flaw in Access Rights Manager
SolarWinds has issued critical security updates to address a high-severity unauthenticated remote code execution vulnerability in its Access Rights Manager (ARM) software. Tracked as **CVE-2026-28326**, the flaw could allow attackers to execute arbitrary code without prior authentication, posing a significant risk to affected systems. Users are strongly advised to update their installations immediately.

**SolarWinds** has released urgent security updates to address a high-severity flaw within its **Access Rights Manager (ARM)**. This vulnerability, if exploited, could lead to unauthenticated remote code execution (RCE).
### Critical RCE Identified
The flaw, identified as **CVE-2026-28326**, carries a CVSS score of 8.8 out of 10.0, highlighting its significant risk. All versions of **Access Rights Manager 2026.2** and earlier are affected.
According to **SolarWinds**' advisory released on September 17, 2026, the issue stems from a hard-coded static key, which an attacker could potentially leverage to gain unauthorized access and execute malicious code.
### Researcher Credited, No In-The-Wild Exploitation
Security researcher **Kai Huang** from **Armadin** is credited with discovering and reporting the vulnerability. **SolarWinds** has since patched the flaw in **ARM 2026.2.1**. Importantly, there is currently no indication that **CVE-2026-28326** has been exploited in the wild.
### Broader Security Updates
This update follows a series of other critical fixes from **SolarWinds** in recent months. Nearly two months prior, the company addressed a critical flaw in **Web Help Desk (WHD)**, **CVE-2026-28323** (CVSS score: 9.8), which could enable a SAML authentication bypass when SAML 2.0 is active.
Another **WHD** vulnerability, **CVE-2026-28299** (CVSS score: 8.2), was a denial-of-service (DoS) flaw that could crash the server due to insufficient memory. Both **WHD** issues were resolved in **WHD 2026.2.1**.
Furthermore, **SolarWinds** has also released patches for 16 vulnerabilities impacting **Serv-U** (including **CVE-2026-28302**, **CVE-2026-28304** through **CVE-2026-28317**, **CVE-2026-28321**, and **CVE-2026-28323**). These **Serv-U** flaws encompassed a range of issues, from privilege escalation and remote code execution to the creation of unauthorized administrator accounts.
Organizations utilizing **SolarWinds ARM**, **WHD**, or **Serv-U** products are urged to apply the latest security updates without delay to mitigate potential risks.