security1 publisher
Hard-coded static key in SolarWinds Access Rights Manager hands unauthenticated attackers RCE
CVE-2026-28326 scores 8.8 and affects every build of Access Rights Manager up to 2026.2. The fix is ARM 2026.2.1, and it lands weeks after SolarWinds patched a SAML bypass in Web Help Desk and 16 flaws in Serv-U.
Publishers:thehackernews.com
Reality
- Evidence52
- Adoption22
- Hype gap+12
- Incentives55
- Confidence58