SolarWinds has issued security updates to remediate CVE-2026-28326, a high-severity flaw residing in Access Rights Manager (ARM) stemming from hard-coded credentials embedded within the product. The vulnerability carries a CVSS score of 8.8 and affects all ARM versions up to and including 2026.2.
Successful exploitation would permit an unauthenticated remote attacker to achieve remote code execution on affected systems without any prior authentication. Patches were disclosed publicly on 17 September 2026, with SolarWinds releasing fixes two days later on 19 September 2026. No exploit code is currently reported as available in the wild, though the unauthenticated nature of the attack vector makes this a target of significant concern.
Given SolarWinds' history as a high-value target for sophisticated threat actors, organisations running ARM 2026.2 or earlier should treat patch application as a priority. The hard-coded credentials mechanism presents a straightforward attack path, and the risk of exploitation is likely to increase as technical details become more widely circulated.
Each brief contains detailed narrative, impact assessments, technical analysis, IOCs and response recommendations, all available inside the Deltabridge platform.
We use analytics cookies to understand how visitors use Deltabridge and improve the site. They’re off until you accept. See our Privacy Policy.