SolarWinds fixes high-severity ARM hard-coded key vulnerability

ARM update addresses unauthenticated remote code execution risk
SolarWinds has released an update for a high-severity vulnerability in Access Rights Manager (ARM) that could enable unauthenticated remote code execution. The flaw, tracked as CVE-2026-28326, has a CVSS score of 8.8 out of 10.0 and affects all ARM versions 2026.2 and earlier.
The company fixed the issue in ARM 2026.2.1. SolarWinds said the weakness stems from a hard-coded static key, creating the conditions for an unauthenticated attacker to execute code remotely if the vulnerability is successfully exploited.
Armadin security researcher Kai Huang discovered and reported the flaw. SolarWinds' advisory, issued on September 17, 2026, does not mention any exploitation of CVE-2026-28326 in the wild.
Part of a broader SolarWinds patch cycle
The ARM release follows fixes issued nearly two months earlier for two vulnerabilities in SolarWinds Web Help Desk (WHD). One, CVE-2026-28323, received a critical CVSS score of 9.8 and could permit a SAML authentication bypass when the SAML 2.0 authentication method is enabled.
The second WHD issue, CVE-2026-28299, is a denial-of-service vulnerability with a CVSS score of 8.2. SolarWinds said insufficient memory could cause the Web Help Desk server to crash. Both WHD vulnerabilities were resolved in version 2026.2.1.
SolarWinds also released fixes for 16 vulnerabilities affecting Serv-U. The company said the issues could lead to privilege escalation, remote code execution, and the creation of administrator accounts. The Serv-U set includes CVE-2026-28302, CVE-2026-28304 through CVE-2026-28317, CVE-2026-28321, and CVE-2026-28323.
What security teams should do
Organizations using Access Rights Manager should establish whether versions 2026.2 or earlier remain deployed and move affected systems to ARM 2026.2.1. The absence of reported in-the-wild exploitation does not change the severity of an unauthenticated code-execution condition.
Security and operations teams can also use this patch cycle to review Web Help Desk and Serv-U inventories, confirm the applicable 2026.2.1 updates, and record completed remediation. Maintaining an accurate product inventory and prompt update process is the practical business implication of these related SolarWinds fixes.

