Threat Intelligence

SolarWinds Fixes Critical Flaw Letting Attackers Take Over Access Rights Manager Without Login

The Hacker News · 19 Sept 2026
Key Takeaway If your business uses SolarWinds Access Rights Manager, update to version 2026.2.1 immediately to close this unauthenticated remote access risk.

SolarWinds has released a security update to fix a serious flaw in its Access Rights Manager (ARM) product, which manages user permissions across an organisation's IT systems. The vulnerability, tracked as CVE-2026-28326 and rated 8.8 out of 10 for severity, was caused by a hard-coded static key built into the software. This weakness could allow an attacker to remotely run malicious code on affected systems without needing valid login credentials.

The flaw affects all versions of ARM up to and including 2026.2, and has been fixed in the newly released 2026.2.1 update. SolarWinds credited security researcher Kai Huang for reporting the issue and stated there is currently no evidence it has been exploited by attackers.

This patch follows other recent fixes from SolarWinds, including a critical SAML authentication bypass and a denial-of-service issue in its Web Help Desk product, as well as 16 separate vulnerabilities in Serv-U that could lead to privilege escalation, remote code execution, and unauthorised admin account creation.

SolarWinds vulnerability remote code execution patch management Access Rights Manager

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.