← All briefs
Brief·2 sources19 Sept 2026

CVE-2026-28326 Patched In SolarWinds ARM Enabling Unauthenticated RCE

vulnerability-disclosurepatch-managementinitial-access

Summary

SolarWinds has issued security updates to remediate CVE-2026-28326, a high-severity flaw residing in Access Rights Manager (ARM) stemming from hard-coded credentials embedded within the product. The vulnerability carries a CVSS score of 8.8 and affects all ARM versions up to and including 2026.2.

Successful exploitation would permit an unauthenticated remote attacker to achieve remote code execution on affected systems without any prior authentication. Patches were disclosed publicly on 17 September 2026, with SolarWinds releasing fixes two days later on 19 September 2026. No exploit code is currently reported as available in the wild, though the unauthenticated nature of the attack vector makes this a target of significant concern.

Given SolarWinds' history as a high-value target for sophisticated threat actors, organisations running ARM 2026.2 or earlier should treat patch application as a priority. The hard-coded credentials mechanism presents a straightforward attack path, and the risk of exploitation is likely to increase as technical details become more widely circulated.

Timeline

  1. 19 September 2026
    SolarWinds releases security patch for ARM
    SolarWinds publishes a security update addressing CVE-2026-28326, covering all Access Rights Manager versions up to and including 2026.2. The advisory confirms the unauthenticated remote code execution potential.
  2. 17 September 2026
    CVE-2026-28326 registered on VulDB
    The vulnerability is publicly catalogued on VulDB, describing hard-coded credentials in SolarWinds Access Rights Manager exploitable remotely. No exploit is noted as available at this stage.

Want the full picture?

Each brief contains detailed narrative, impact assessments, technical analysis, IOCs and response recommendations, all available inside the Deltabridge platform.