LIVE · cybersecurity feed
Live wire
CVE-2026-9055 · WordPress Amelia Plugin Flaw Exploited Before CVE PublicationCVE-2026-46331 · Linux Kernel Flaw Exploited After 71 Days, Not on CISA KEVCVE-2026-84434 · CVE-2026-84434 Exploited Before Publication, No Patch WindowCVE-2017-20284 · CVE-2017-20284 Exploited Same Day as PublicationCVE-2026-87886 · Acronis Backup Flaw Exploited Before CVE PublicationCVE-2026-76461 · Week in review: Cisco patches exploited email gateway 0-day, Revolut breachCVE-2024-4405 · Malicious Extensions Hijack AI Browser Agents via Prompt ForcingAgentic security is the billion-dollar challenge for some clever startup to solveIdentity Visibility in 2026: The Foundation of Identity SecurityCVE-2026-28299 · SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE
CVE-2026-28299high

SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE

SolarWinds has issued a patch for a critical vulnerability in its Access Rights Manager (ARM) software. The flaw, identified as CVE-2026-28299, allows for unauthenticated remote code execution due to a hard-coded static key. This vulnerability affects all versions of ARM prior to 2026.2.1. The company also recently addressed other significant vulnerabilities in its Web Help Desk and Serv-U products.

zeroday.news ·

SolarWinds has released a patch for a critical vulnerability in its Access Rights Manager (ARM) software. The flaw, designated CVE-2026-28299, enables unauthenticated remote code execution. This issue stems from the presence of a hard-coded static key within the software. All versions of ARM preceding 2026.2.1 are affected by this vulnerability.

The technical mechanism behind this vulnerability involves a hard-coded static key. In software development, hard-coded keys are often used for various internal functions, such as encryption, authentication, or session management. When such a key is static and discoverable, an attacker can potentially leverage it to bypass security controls. In this specific instance, the presence of a hard-coded static key allows an attacker to achieve unauthenticated remote code execution, meaning they can run arbitrary commands on the affected system without needing to provide valid credentials.

The affected product is SolarWinds Access Rights Manager (ARM). ARM is designed to help organizations manage and audit user access rights across their IT infrastructure, providing visibility into who has access to what resources. Given its role in access management, a remote code execution vulnerability in ARM could have significant implications for an organization's security posture.

The scope of this vulnerability encompasses all versions of SolarWinds ARM prior to version 2026.2.1. Organizations utilizing any older iteration of the software are advised to update their installations promptly. Remote code execution flaws are generally considered among the most severe, as they can lead to full system compromise, data exfiltration, or the deployment of further malicious payloads.

Typical mitigation guidance for vulnerabilities of this class involves applying vendor-supplied patches as soon as they become available. Organizations should also ensure that their network segmentation practices limit exposure of management interfaces, such as those for ARM, to untrusted networks. Regular security audits and penetration testing can help identify similar weaknesses before they are exploited.

This patch for ARM follows other recent security advisories from SolarWinds. The company has also addressed significant vulnerabilities in its Web Help Desk and Serv-U products. This series of patches underscores the ongoing challenge for software vendors to identify and remediate critical security flaws, particularly in products that manage core IT infrastructure components.

vulnerabilities in this storyCVE-2026-28299CVE-2026-28326CVE-2026-28323CVE-2026-28302CVE-2026-28304CVE-2026-28317CVE-2026-28321
solarwindsaccess rights managerrcevulnerabilitypatch
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

U.S. CISA adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added [1, 2] the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: Below are detailed descriptions of the flaws: At the time of this writing, there are currently no details

malware

Malicious npm packages evade install-script defenses at runtime

An ongoing npm malware campaign involving the 'indexed-btree' package shows how threat actors bypass supply chain defenses by hiding malicious code in a package's normal runtime behavior rather than in installation scripts. [...]

nation-state

AI Hallucinations Nearly Triggered a US-China Military Confrontation

An AI-generated intelligence report falsely identified weapons on a Chinese ship, nearly triggering a US military operation during the Iran war. According to CNN, four sources familiar with the episode say an intelligence report circulated through the military claiming a Chinese vessel in the Middle East was carrying components for a nuclear weapons program. The […]

vulnerability

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 115

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Gray Rabbits and the Tale of a One-Click Backdoor Red Heron exploits Gitea n-day flaw in multinational campaign, exposing new Linux rootkit Malicious Twitch Browser Extension Exposes 30,000 Users’ OAuth Tokens to Russian Bot […]

patch

Researchers escape OpenAI Codex sandbox to run commands on host

Researchers escaped OpenAI's Codex sandbox two ways, one running commands on a developer's machine from its most locked-down mode. OpenAI has patched both. [...]

CVE-2026-9055critical

WordPress Amelia Plugin Flaw Exploited Before CVE Publication

A critical privilege escalation vulnerability in the WordPress Amelia plugin was exploited before its official CVE publication. CISA has not yet added it to its Known Exploited Vulnerabilities catalog.