Critical Unauthenticated RCE in SolarWinds Access Rights Manager (CVE‑2026‑28326)
What It Is — SolarWinds disclosed a high‑severity flaw (CVE‑2026‑28326) in its Access Rights Manager (ARM) that allows an attacker to execute arbitrary code on the target system without authentication.
Exploitability — The vulnerability scores 8.8 / 10.0 on CVSS v3.1. Public proof‑of‑concept code has not been released, but the unauthenticated nature makes it trivially exploitable once a vulnerable instance is reachable.
Affected Products — SolarWinds Access Rights Manager 2026.2 and all earlier releases.
Why It Matters for Trust & Control Assurance
- Vulnerability Management – The flaw tests the control objective of maintaining a robust patch‑management process and continuous monitoring of third‑party components.
- Evidence of Due Diligence – Demonstrating timely remediation provides auditable proof that your organization actively manages supply‑chain risk.
- Defensible Audit Trail – Documented patch‑deployment and verification logs satisfy multiple frameworks that require evidence of control effectiveness (e.g., NIST CSF, ISO 27001).
Recommended Actions
- Identify every asset running SolarWinds ARM 2026.2 or earlier.
- Apply the vendor‑supplied security update immediately; verify the installed version.
- Capture and retain patch‑deployment logs as evidence for audit purposes.
- Update your vulnerability‑management inventory and schedule regular scans for unpatched third‑party software.
- Monitor network and host logs for any anomalous activity that could indicate exploitation attempts.
Source: The Hacker News – SolarWinds patches ARM hard‑coded key flaw