AI Weekly Malaysia

Back to items Summaries

SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE

ID
26308
Status
summarized
Published
19 Sep 2026, 5:31 PM
Fetched
19 Sep 2026, 9:29 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/solarwinds-patches-arm-hard-coded-key.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
3.0
Created
19 Sep 2026, 9:30 PM
Tags
Audience
developers

What happened

SolarWinds patched a high-severity unauthenticated RCE flaw (CVE-2026-28326, CVSS 8.8) in Access Rights Manager caused by a hard-coded static key, affecting all ARM versions 2026.2 and prior, fixed in ARM 2026.2.1. The company also shipped fixes for a critical SAML authentication bypass in Web Help Desk (CVE-2026-28323, CVSS 9.8) and 16 flaws in Serv-U enabling privilege escalation and admin account creation.

Why it matters

If your organization runs SolarWinds ARM, WHD, or Serv-U, patch to ARM 2026.2.1, WHD 2026.2.1, and the latest Serv-U immediately—unauthenticated RCE from a hard-coded key requires no credentials and is trivially exploitable. For most builders not running these products, no action is needed.

Discussion angle

Hard-coded cryptographic keys in shipped enterprise software remain a recurring failure mode—worth a quick discussion on how to avoid this in your own codebase via secrets management and CI checks.

Top