SolarWinds has released important security updates to address a high-severity vulnerability in its Access Rights Manager (ARM) product. The flaw could allow attackers to execute malicious code remotely without authentication, making it a significant security concern for organizations using affected versions of the software.
The vulnerability, tracked as CVE-2026-28326, has received a CVSS score of 8.8, indicating a high level of severity. According to SolarWinds, all versions of Access Rights Manager 2026.2 and earlier are affected.
The newly disclosed vulnerability is an unauthenticated remote code execution (RCE) flaw. Remote code execution vulnerabilities are among the most dangerous security issues because they can allow attackers to run arbitrary code on a targeted system from a remote location.
In its security advisory, SolarWinds stated that the issue is linked to a hard-coded static key within the product. Hard-coded keys can create security risks because they remain unchanged and may be discovered or abused by attackers to gain unauthorized access to critical functions.
If successfully exploited, the flaw could potentially enable threat actors to execute malicious commands on vulnerable systems without needing valid login credentials.
The company has addressed the issue in Access Rights Manager version 2026.2.1 and is urging customers to upgrade as soon as possible.
SolarWinds credited Kai Huang, a security researcher from Armadin, for discovering and responsibly reporting the vulnerability.
Responsible disclosure plays a critical role in cybersecurity by allowing vendors to identify and fix security weaknesses before they can be widely exploited by malicious actors. Such collaboration between security researchers and software vendors helps strengthen the overall security ecosystem.
At the time of disclosure, SolarWinds stated that it has no evidence suggesting the vulnerability has been actively exploited in the wild. However, organizations should not delay patching because publicly disclosed vulnerabilities often attract attention from cybercriminals looking for potential targets.
Access Rights Manager is widely used by organizations to manage user permissions, access rights, and identity governance across IT environments.
Because the vulnerability can be exploited without authentication, attackers may not require legitimate credentials to launch an attack. This significantly increases the risk level, especially for internet-facing or poorly segmented environments.
Potential consequences of a successful attack could include:
- Unauthorized access to sensitive systems
- Execution of malicious code
- Compromise of user accounts and permissions
- Deployment of malware or ransomware
- Disruption of business operations
Security teams should review their environments immediately and ensure that all affected systems are updated to the latest version.
The latest patch comes less than two months after SolarWinds addressed another critical vulnerability affecting its Web Help Desk (WHD) platform.
That flaw, identified as CVE-2026-28323, received a CVSS score of 9.8, placing it in the critical severity category. The vulnerability could allow a SAML authentication bypass when the SAML 2.0 authentication method is enabled.
Authentication bypass vulnerabilities are particularly dangerous because they may allow attackers to gain access without completing normal login procedures. In environments that rely on single sign-on (SSO) and federated identity systems, such weaknesses can create serious security risks.
SolarWinds resolved the issue in Web Help Desk 2026.2.1.
Alongside the authentication bypass flaw, SolarWinds also fixed a high-severity Denial-of-Service (DoS) vulnerability tracked as CVE-2026-28299.
The vulnerability carries a CVSS score of 8.2 and could cause a Web Help Desk server to crash due to insufficient memory resources.
A successful denial-of-service attack can impact business continuity by making critical services unavailable to employees and customers. SolarWinds has fixed this issue in Web Help Desk version 2026.2.1.
In addition to Access Rights Manager and Web Help Desk, SolarWinds has released fixes for 16 vulnerabilities affecting Serv-U, its managed file transfer solution.
The vulnerabilities include:
- Privilege escalation flaws
- Remote code execution vulnerabilities
- Security weaknesses that could enable the creation of administrator accounts
- Other issues affecting system integrity and access control
The affected vulnerabilities include:
- CVE-2026-28302
- CVE-2026-28304 through CVE-2026-28317
- CVE-2026-28321
- CVE-2026-28323
While SolarWinds has not reported active exploitation of these flaws, organizations using Serv-U should prioritize applying the latest updates to reduce exposure to potential attacks.
Security teams using SolarWinds products should take the following steps immediately:
- Upgrade Access Rights Manager to version 2026.2.1 or later.
- Update Web Help Desk to version 2026.2.1.
- Apply the latest Serv-U security patches.
- Review systems for unusual activity or unauthorized access attempts.
- Restrict exposure of management interfaces to the internet wherever possible.
- Implement network segmentation and least-privilege access controls.
- Monitor vendor advisories for future security updates.
The latest SolarWinds security updates address several high-risk vulnerabilities across Access Rights Manager, Web Help Desk, and Serv-U. The most significant issue, CVE-2026-28326, could allow unauthenticated remote code execution through a hard-coded static key, making prompt remediation essential.
Although there is currently no indication that these vulnerabilities are being actively exploited, organizations should treat the updates as a priority. Timely patching, continuous monitoring, and strong access controls remain key defenses against emerging cybersecurity threats.
