DEV Community

Mark0
Mark0

Posted on

SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE

SolarWinds has released critical security updates to address a high-severity vulnerability in its Access Rights Manager (ARM), tracked as CVE-2026-28326 with a CVSS score of 8.8. This flaw allows for unauthenticated remote code execution (RCE) due to the presence of a hard-coded static key within the software. The vulnerability affects all versions of ARM up to 2026.2, and users are urged to update to version 2026.2.1 immediately.

In addition to the ARM patch, the company has addressed several other significant vulnerabilities across its product suite, including a critical SAML authentication bypass in Web Help Desk (WHD) and 16 different flaws in Serv-U. These vulnerabilities could lead to consequences ranging from denial-of-service attacks to privilege escalation and unauthorized administrator account creation. While there are currently no reports of these flaws being exploited in the wild, the severity of the issues necessitates prompt remediation by affected organizations.


Read Full Article

Top comments (0)