CVE-2026-28326
SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability. The issue stems from a hardcoded static key.
- Published Sep 17, 2026
- CVSS 8.8 high
- 0.7% chance of exploitation in the next 30 days (EPSS)
Affected software
In the news
- Vulnerability in SolarWinds Access Rights Manager CERT-FR ·
- ⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks The Hacker News ·
- SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE The Hacker News ·
- SolarWinds security advisory (AV26-941) Canadian Centre for Cyber Security ·