LIVE · cybersecurity feed
Live wire
CVE-2026-9055 · WordPress Amelia Plugin Flaw Exploited Before CVE PublicationCVE-2026-46331 · Linux Kernel Flaw Exploited After 71 Days, Not on CISA KEVCVE-2026-84434 · CVE-2026-84434 Exploited Before Publication, No Patch WindowCVE-2017-20284 · CVE-2017-20284 Exploited Same Day as PublicationCVE-2026-87886 · Acronis Backup Flaw Exploited Before CVE PublicationCVE-2026-76461 · Week in review: Cisco patches exploited email gateway 0-day, Revolut breachCVE-2024-4405 · Malicious Extensions Hijack AI Browser Agents via Prompt ForcingAgentic security is the billion-dollar challenge for some clever startup to solveIdentity Visibility in 2026: The Foundation of Identity SecurityCVE-2026-28299 · SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE

solarwinds

1 stories
CVE-2026-28299high

SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE

SolarWinds has issued a patch for a critical vulnerability in its Access Rights Manager (ARM) software. The flaw, identified as CVE-2026-28299, allows for unauthenticated remote code execution due to a hard-coded static key. This vulnerability affects all versions of ARM prior to 2026.2.1. The company also recently addressed other significant vulnerabilities in its Web Help Desk and Serv-U products.