SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE
- ID
- 26308
- Status
- summarized
- Published
- 19 Sep 2026, 5:31 PM
- Fetched
- 19 Sep 2026, 9:29 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/solarwinds-patches-arm-hard-coded-key.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 3.0
- Created
- 19 Sep 2026, 9:30 PM
- Tags
- Audience
- developers
What happened
SolarWinds patched a high-severity unauthenticated RCE flaw (CVE-2026-28326, CVSS 8.8) in Access Rights Manager caused by a hard-coded static key, affecting all ARM versions 2026.2 and prior, fixed in ARM 2026.2.1. The company also shipped fixes for a critical SAML authentication bypass in Web Help Desk (CVE-2026-28323, CVSS 9.8) and 16 flaws in Serv-U enabling privilege escalation and admin account creation.
Why it matters
If your organization runs SolarWinds ARM, WHD, or Serv-U, patch to ARM 2026.2.1, WHD 2026.2.1, and the latest Serv-U immediately—unauthenticated RCE from a hard-coded key requires no credentials and is trivially exploitable. For most builders not running these products, no action is needed.
Discussion angle
Hard-coded cryptographic keys in shipped enterprise software remain a recurring failure mode—worth a quick discussion on how to avoid this in your own codebase via secrets management and CI checks.