Home / Sep 20, 2026 / Story
0
#7 The Hacker News general September 19, 2026 at 09:31 UTC

SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE

By [email protected] (The Hacker News)

AI Summary

SolarWinds patched CVE-2026-28326 (CVSS 8.8), a hard-coded cryptographic key vulnerability in Access Rights Manager (ARM) affecting all versions through 2026.2 that enables unauthenticated remote code execution. ARM is used for privileged access governance, making unauthenticated RCE in this product a high-value target for attackers seeking lateral movement into sensitive identity infrastructure.

Relevance score: 82.0/100

# More from September 20