Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-09-20 · updated: 2026-09-20 · tags: [incident, global] · confidence: high · severity: high · affected_sectors: [global] · au_impact: true

SolarWinds released updates for a high-severity unauthenticated remote code execution flaw in Access Rights Manager (ARM) tracked as CVE-2026-28326 and rated 8.8. The advisory says the issue stems from a hard-coded static key and affects all ARM versions 2026.2 and prior; it is fixed in ARM 2026.2.1, and SolarWinds credits Armadin researcher Kai Huang with the discovery. The vendor makes no mention of exploitation in the wild. The same release cycle resolves a critical SAML authentication bypass in Web Help Desk (CVE-2026-28323, 9.8) that applies when SAML 2.0 authentication is enabled, plus a denial-of-service flaw in the same product (CVE-2026-28299, 8.2), and 16 flaws in Serv-U (CVE-2026-28302, CVE-2026-28304 through CVE-2026-28317, CVE-2026-28321 and CVE-2026-28323) that could enable privilege escalation, remote code execution and the creation of administrator accounts. Access Rights Manager is a privileged identity tool, so an unauthenticated RCE in it is a direct path into the entitlements it exists to govern; SolarWinds patches are also historically attractive to opportunistic actors because of the product's government and enterprise footprint. Both Web Help Desk issues are resolved in WHD 2026.2.1.

Attribute Detail
**Sector Global (Macro)
**Date 2026-09-20
**Source The Hacker News
**Reliability Tier 2
**CVEs CVE-2026-28299, CVE-2026-28302, CVE-2026-28304, CVE-2026-28317, CVE-2026-28321, CVE-2026-28323, CVE-2026-28326