SolarWinds has issued an urgent security update for its Access Rights Manager (ARM) software to fix a severe vulnerability that could grant attackers unauthenticated remote code execution capabilities.

The flaw, tracked as CVE-2026-28326, carries a CVSS score of 8.8, placing it firmly in the high-severity category. The root cause is a hard-coded cryptographic key—a static secret embedded within the software and shared across all installations. This architectural flaw allows a malicious actor to bypass authentication controls entirely.

Because ARM is a privileged administration tool for managing permissions in systems like Active Directory and Azure AD, successful exploitation would be particularly damaging. An attacker could leverage the flaw to gain a highly sensitive foothold, paving the way for privilege escalation and lateral movement throughout a corporate network.

All versions of SolarWinds ARM up to and including 2026.2 are affected. While the vendor's advisory indicates no evidence of active exploitation in the wild, the combination of unauthenticated access and deep system privileges makes the vulnerability a prime target.

The discovery highlights the systemic risk posed by hard-coded credentials, a well-documented security anti-pattern. In this instance, a single secret creates a single point of failure across potentially thousands of deployments.

Applying the official patch from SolarWinds is the only recommended mitigation and must be prioritized. Following the update, administrators should conduct forensic reviews of ARM server logs, looking for any anomalous connection attempts or command executions, to validate the integrity of their environment both before and after remediation.


SolarWinds 為其存取權限管理器 (ARM) 軟件發佈了一項緊急安全更新,以修補一個嚴重漏洞。該漏洞可能賦予攻擊者未經驗證的遠端程式碼執行能力。

該漏洞編號為 CVE-2026-28326,CVSS 評分為 8.8,明確屬於高嚴重性類別。其根本原因是硬編碼加密密鑰——一個嵌入軟件中、所有安裝共用的靜態秘密。此架構缺陷允許惡意行為者完全繞過驗證控制。

由於 ARM 是用於管理如 Active Directory 和 Azure AD 等系統權限的特權管理工具,成功利用此漏洞將造成特別嚴重的後果。攻擊者可藉此漏洞獲取高度敏感的立足點,為權限提升及企業網絡內的橫向移動鋪平道路。

SolarWinds ARM 所有 2026.2 及以下版本均受影響。雖然供應商公告指出未有證據顯示漏洞在野外被活躍利用,但未經驗證的訪問與深度系統權限相結合,使該漏洞成為首要攻擊目標。

此次發現突顯了硬編碼憑證所帶來的系統性風險,這是一個有充分記載的安全反模式。在此案例中,單一秘密在數千個部署中造成了單點故障。

應用 SolarWinds 官方補丁是唯一建議的緩解措施,且必須優先執行。更新後,管理員應對 ARM 伺服器日誌進行取證審查,檢查任何異常連接嘗試或命令執行,以驗證補救前後環境的完整性。

新聞來源 / Original News Source