hacker-news · Crawled Sep 19, 2026
SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE
Read original article ↗AI Summary
SolarWinds has patched a high-severity vulnerability, CVE-2026-28326, in its Access Rights Manager (ARM) product that could allow unauthenticated remote code execution due to a hard-coded static key. The flaw affects all versions prior to 2026.2.1 and has been assigned a CVSS score of 8.8. The vulnerability was discovered and reported by Armadin security researcher Kai Huang, but there is no evidence of in-the-wild exploitation to date.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.