← Back to the CVE Tracker
SolarWinds has issued a patch for a critical vulnerability in its Access Rights Manager (ARM) software. The flaw, identified as CVE-2026-28299, allows for unauthenticated remote code execution due to a hard-coded static key. This vulnerability affects all versions of ARM prior to 2026.2.1. The company also recently addressed other significant vulnerabilities in its Web Help Desk and Serv-U products.