SolarWinds has released critical security updates to address a high-severity remote code execution (RCE) vulnerability in its Access Rights Manager (ARM) software. Tracked as CVE-2026-28326, the flaw originates from a hard-coded static key, potentially allowing unauthenticated attackers to execute arbitrary code. The vulnerability impacts all versions of ARM up to 2026.2 and has been patched in version 2026.2.1.
In addition to the ARM update, SolarWinds recently resolved multiple vulnerabilities across its Web Help Desk (WHD) and Serv-U product lines. These include a critical SAML authentication bypass and various flaws leading to privilege escalation or denial-of-service. Security administrators are urged to apply the latest patches to mitigate risks across their infrastructure.
Top comments (0)