SolarWinds has released security updates to address a high severity vulnerability affecting its Access Rights Manager (ARM) platform that could potentially allow unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-28326, has been assigned a CVSS score of 8.8 out of 10.0, indicating a significant security risk. The issue affects all versions of Access Rights Manager 2026.2 and earlier releases. SolarWinds has provided a security update to address the flaw and has not reported any evidence that the vulnerability has been exploited in active attacks.
According to SolarWinds’ security advisory published on September 17, 2026, the vulnerability was caused by a hard-coded static key within Access Rights Manager. The company stated that the issue could allow an unauthenticated remote code execution scenario if successfully exploited. Access Rights Manager is a solution designed to help organizations manage and monitor access permissions across enterprise environments, making security updates important for organizations using affected versions of the platform. SolarWinds credited security researcher Kai Huang from Armadin for identifying and reporting the vulnerability through responsible disclosure. The flaw has been resolved through the release of ARM 2026.2.1, which includes the necessary security improvements.
The latest update follows previous security fixes released by SolarWinds for other products. Nearly two months earlier, the company addressed a critical vulnerability affecting Web Help Desk (WHD), tracked as CVE-2026-28323, which carried a CVSS score of 9.8. That issue could result in a SAML authentication bypass in environments where the SAML 2.0 authentication method was enabled. SolarWinds also resolved another Web Help Desk vulnerability, tracked as CVE-2026-28299, with a CVSS score of 8.2. The flaw was related to denial-of-service conditions that could cause a Web Help Desk server to crash because of insufficient memory handling. Both vulnerabilities were fixed in WHD 2026.2.1.
In addition to the Access Rights Manager and Web Help Desk updates, SolarWinds has also released security fixes addressing multiple vulnerabilities affecting its Serv-U product. The company issued patches for 16 flaws, including CVE-2026-28302, CVE-2026-28304 through CVE-2026-28317, CVE-2026-28321, and CVE-2026-28323. These vulnerabilities could potentially lead to security issues such as privilege escalation, remote code execution, and unauthorized creation of administrator accounts. The updates highlight the importance of maintaining current software versions and applying vendor-provided patches to reduce exposure to known vulnerabilities. Organizations using SolarWinds products are advised to review available security updates and upgrade affected systems to supported versions to strengthen their enterprise security posture.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.





