type: cve · created: 2026-09-20 · updated: 2026-09-20 · tags: [cve] · confidence: high · severity: high · affected_sectors: [global] · au_impact: false
SolarWinds released updates for a high-severity unauthenticated remote code execution flaw in Access Rights Manager (ARM) tracked as CVE-2026-28326 and rated 8.8.
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-28326 |
| CVSS | 8.8 (CVSS 3.1, High) |
| Vendor / product | SolarWinds Access Rights Manager |
| Reported | 2026-09-20 |
NVD description
SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability. The issue stems from a hardcoded static key.