Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4508 articles · 223849 vulns · 37/41 feeds (7d)
← Back to list
8.8
CVE-2026-28326PATCHED
solarwinds · access rights manager

SolarWinds Access Rights Manager Unauthenticated Remote Code Execution Vulnerability

Description

SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability. The issue stems from a hardcoded static key.

Affected Products

VendorProductVersions
solarwindsaccess rights manager2026.2 and all previous versions

References

  • https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28326(vendor-advisory)
  • https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/arm_2026-2-1_release_notes.htm(release-notes)
  • https://documentation.solarwinds.com/en/success_center/arm/content/secure-your-arm-deployment.htm(x_secure-configuration-guide)

Related News (6 articles)

Tier D
SecurityWeek3d ago
SolarWinds Patches Critical RCE Flaws in Observability Self-Hosted
→ No new info (linked only)
Tier B
CERT-FR6d ago
Vulnérabilité dans SolarWinds Access Rights Manager (22 septembre 2026)
→ No new info (linked only)
Tier D
Heise Security6d ago
Fremdzugriffe auf SolarWinds Access Rights Manager vorstellbar
→ No new info (linked only)
Tier D
The Hacker News8d ago
SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE
→ No new info (linked only)
Tier B
CCCS Canada9d ago
SolarWinds security advisory (AV26-941)
→ No new info (linked only)
Tier C
VulDB10d ago
CVE-2026-28326 | SolarWinds Access Rights Manager hard-coded credentials
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.18.8 HIGH
VectorCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28326
CWECWE-321
PublishedSep 17, 2026
Trending Score37
Source articles6
Independent6
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-28324
SolarWinds Observability Self-Hosted Remote Code Execution Vulnerability
Trending: 44
HIGHCVE-2026-28325
SolarWinds Observability Self-Hosted Unauthenticated Remote Code Execution Vulnerability
Trending: 35
MEDIUMCVE-2026-28315
SolarWinds Serv-U Authenticated Stored Cross-site Scripting (XSS) Vulnerability
CRITICALCVE-2026-28302
SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability
CRITICALCVE-2026-28305
SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 17, 2026
Discovered by ZDM
Sep 17, 2026
Patch Available
Sep 18, 2026