Skip to main content
CybersecurityVulnerability Management

SolarWinds Fixes Hard-Coded Key Flaw in Access Rights Manager

Server room equipment with a central computer server in sharp focus.

"SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability," SolarWinds said in an advisory released on September 17, 2026.

CVE-2026-28326: hard-coded static key led to unauthenticated RCE

SolarWinds disclosed a high-severity vulnerability in Access Rights Manager (ARM) that the company says stems from "a hard-coded static key." The flaw is tracked as CVE-2026-28326 and carries a CVSS score of 8.8 out of 10.0. According to the advisory, all versions of Access Rights Manager 2026.2 and prior are affected. SolarWinds patched the issue in ARM 2026.2.1, and credited Armadin security researcher Kai Huang with discovering and reporting the vulnerability. The company made no mention of the flaw being exploited in the wild.

Web Help Desk fixes: SAML bypass and a memory-related DoS

The ARM advisory follows a string of recent updates from SolarWinds. Nearly two months earlier the company shipped fixes for a critical vulnerability in Web Help Desk (WHD) identified as CVE-2026-28323, rated 9.8 on the CVSS scale, that could result in a SAML authentication bypass when the SAML 2.0 authentication method is enabled. SolarWinds also resolved a denial-of-service issue, CVE-2026-28299 (CVSS 8.2), that could cause the Web Help Desk server to crash due to insufficient memory. Both of those issues were addressed in WHD 2026.2.1.

Serv-U updates: 16 flaws covering privilege escalation, RCE, and admin account creation

In the same wave of patches, SolarWinds released fixes for 16 vulnerabilities affecting Serv-U. The CVEs listed by the company include CVE-2026-28302, CVE-2026-28304 through CVE-2026-28317, CVE-2026-28321, and CVE-2026-28323. SolarWinds says these issues could allow privilege escalation, remote code execution, and the creation of administrator accounts. The company published the fixes as part of its recent product updates.

What this means for technologists, affected enterprises, and procurement leaders

  • Technologists and security teams: Organizations running Access Rights Manager versions up through 2026.2 should install ARM 2026.2.1 to remediate CVE-2026-28326; teams that operate Web Help Desk and Serv-U should verify they are running the respective patched releases (WHD 2026.2.1 and the Serv-U fixes) to address the SAML bypass, DoS, and the range of Serv-U issues.
  • Affected enterprises and procurement leaders: The set of patches across ARM, WHD, and Serv-U underscores the importance of tracking vendor advisories and versioning — in this case the identifying markers are ARM 2026.2.1 and WHD 2026.2.1 — and confirming that deployed instances have been updated, particularly when unauthenticated remote code execution and authentication bypass conditions are involved.
  • End users and general administrators: SolarWinds' advisory noted the cause as a hard-coded static key for ARM and explicitly did not report exploitation in the wild; nonetheless, the severity ratings (CVSS 8.8 and 9.8 for the most critical items) indicate the technical urgency of applying the supplied patches.

SolarWinds has addressed a compact but serious cluster of flaws across three product lines in a short interval. The company patched the hard-coded-key issue in ARM 2026.2.1, credited an external researcher for the discovery, and affirmed fixes for the earlier WHD and Serv-U vulnerabilities. Absent any reported in-the-wild exploitation in the advisory, the immediate requirement on affected organizations is to confirm deployment of the indicated patched versions and to treat the CVE identifiers — CVE-2026-28326 for ARM and the related CVEs for WHD and Serv-U — as the operative references for remediation.

Original story at The Hacker News