Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

Critical Unauthenticated RCE in SolarWinds Access Rights Manager (CVE‑2026‑28326)

SolarWinds released a fix for CVE‑2026‑28326, an unauthenticated remote code execution flaw affecting all Access Rights Manager 2026.2 and earlier versions. The issue underscores the need for continuous vulnerability management and auditable patch‑deployment evidence.

LiveThreat™ Intelligence · 📅 September 19, 2026· 📰 thehackernews.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
5 recommended
📰
Source
thehackernews.com

Critical Unauthenticated RCE in SolarWinds Access Rights Manager (CVE‑2026‑28326)

What It Is — SolarWinds disclosed a high‑severity flaw (CVE‑2026‑28326) in its Access Rights Manager (ARM) that allows an attacker to execute arbitrary code on the target system without authentication.

Exploitability — The vulnerability scores 8.8 / 10.0 on CVSS v3.1. Public proof‑of‑concept code has not been released, but the unauthenticated nature makes it trivially exploitable once a vulnerable instance is reachable.

Affected Products — SolarWinds Access Rights Manager 2026.2 and all earlier releases.

Why It Matters for Trust & Control Assurance

  • Vulnerability Management – The flaw tests the control objective of maintaining a robust patch‑management process and continuous monitoring of third‑party components.
  • Evidence of Due Diligence – Demonstrating timely remediation provides auditable proof that your organization actively manages supply‑chain risk.
  • Defensible Audit Trail – Documented patch‑deployment and verification logs satisfy multiple frameworks that require evidence of control effectiveness (e.g., NIST CSF, ISO 27001).

Recommended Actions

  • Identify every asset running SolarWinds ARM 2026.2 or earlier.
  • Apply the vendor‑supplied security update immediately; verify the installed version.
  • Capture and retain patch‑deployment logs as evidence for audit purposes.
  • Update your vulnerability‑management inventory and schedule regular scans for unpatched third‑party software.
  • Monitor network and host logs for any anomalous activity that could indicate exploitation attempts.

Source: The Hacker News – SolarWinds patches ARM hard‑coded key flaw

📰 Original Source
https://thehackernews.com/2026/09/solarwinds-patches-arm-hard-coded-key.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →