{"id":3010,"date":"2026-09-19T13:17:21","date_gmt":"2026-09-19T13:17:21","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=3010"},"modified":"2026-09-19T13:17:21","modified_gmt":"2026-09-19T13:17:21","slug":"solarwinds-patches-arm-hard-coded-key-flaw-enabling-unauthenticated-rce","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=3010","title":{"rendered":"SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Sep 19, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ Identity Security<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjXW-SaTg898BaxxlrDjSCrcm6ZYDgxoeuYCBY4QNWs6Nt5RhyphenhyphenCf4iSIyodz-7jk8rTqUT8hjlMT74dIf6ZjL_pD5NmiNbAHhsZwzw2rakJUDaU1tVeEvKw7Az3tMf34Xwh3ffToJeI1tpTQ8rAR8AvVn2XTupFgfhehb9sHClHDDGeDd4Y9z4oUf5CYPoS\/s1700-nu-rw-lo-l85-e365\/solar.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>SolarWinds has released security updates to address a high-severity flaw in Access Rights Manager (ARM) that, if successfully exploited, could lead to an unauthenticated remote code execution vulnerability.<\/p>\n<p>The vulnerability, tracked as <strong><a href=\"https:\/\/www.solarwinds.com\/trust-center\/security-advisories\/cve-2026-28326\" target=\"_blank\">CVE-2026-28326<\/a><\/strong>, is rated 8.8 out of 10.0 on the CVSS scoring system. The issue affects all versions of Access Rights Manager 2026.2 and prior.<\/p>\n<p>\u00abSolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability,\u00bb SolarWinds said in an advisory released on September 17, 2026. \u00abThe issue stems from a hard-coded static key.\u00bb<\/p>\n<p>The company credited Armadin security researcher Kai Huang with discovering and reporting the flaw, which has been <a href=\"https:\/\/documentation.solarwinds.com\/en\/success_center\/arm\/content\/release_notes\/arm_2026-2-1_release_notes.htm\" target=\"_blank\">patched in ARM 2026.2.1<\/a>. SolarWinds makes no mention of the vulnerability being exploited in the wild.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/trust-world-update-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhYq3TvePXpW0JIC7fXyv7A1W8KQqmb-AZqza2EuPyT0k8Nm5CwHYHISFLKXSKIAyR8JRtqEFQ4zx5jADiAkZKQ08nRWG1jCRV5YAbhKua7WaDdH1L6wsI-xOkoV4brlMfK44UwU-4Q1xqWg0uNN7sZkMCzci4RXYgWMNPHTtuKua7OR4oCbmxE10u0yKnR\/s728-nu-rw-lo-l85-e365\/tl-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The development comes nearly two months after the company <a href=\"https:\/\/www.solarwinds.com\/trust-center\/security-advisories\" target=\"_blank\">shipped<\/a> fixes for a critical flaw impacting Web Help Desk (WHD) (CVE-2026-28323, CVSS score: 9.8) that could result in a SAML authentication bypass when the SAML 2.0 authentication method is enabled.<\/p>\n<p>Another vulnerability relates to a denial-of-service (DoS) vulnerability (CVE-2026-28299, CVSS score: 8.2) that could cause the Web Help Desk server to crash due to insufficient memory. Both issues have been resolved in WHD 2026.2.1.<\/p>\n<p>SolarWinds has also released fixes for 16 flaws impacting Serv-U (CVE-2026-28302, from CVE-2026-28304 through CVE-2026-28317, CVE-2026-28321, CVE-2026-28323) that could lead to privilege escalation, remote code execution, and the creation of administrator accounts. <\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Sep 19, 2026Vulnerability \/ Identity Security SolarWinds has released security updates to address a high-severity flaw in Access Rights Manager (ARM) that, if successfully exploited, could lead to an&hellip;<\/p>\n","protected":false},"author":1,"featured_media":3011,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[3469,524,70,3470,15,57,316,56,725],"class_list":["post-3010","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-arm","tag-enabling","tag-flaw","tag-hardcoded","tag-key","tag-patches","tag-rce","tag-solarwinds","tag-unauthenticated"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/3010","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3010"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/3010\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/3011"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3010"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3010"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3010"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}