Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Cultural treasures are being destroyed by war, and people want justice

    September 20, 2026

    Meta’s Muse is creepy, but maybe not for the reasons you think

    September 20, 2026

    CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild

    September 20, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Cultural treasures are being destroyed by war, and people want justice
    • Meta’s Muse is creepy, but maybe not for the reasons you think
    • CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild
    • Gen Z are investing like Boomers
    • Saudi-led coalition says defences intercept Houthi missile fired at Riyadh | Houthis News
    • Kemi Badenoch accuses Andy Burnham of ‘fiddling while Europe risks burning’ | Kemi Badenoch
    • eBay Coupons: 20% Off in September 2026
    • SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Sunday, September 20
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 19, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananSep 19, 2026Vulnerability / Identity Security

    SolarWinds has released security updates to address a high-severity flaw in Access Rights Manager (ARM) that, if successfully exploited, could lead to an unauthenticated remote code execution vulnerability.

    The vulnerability, tracked as CVE-2026-28326, is rated 8.8 out of 10.0 on the CVSS scoring system. The issue affects all versions of Access Rights Manager 2026.2 and prior.

    “SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability,” SolarWinds said in an advisory released on September 17, 2026. “The issue stems from a hard-coded static key.”

    The company credited Armadin security researcher Kai Huang with discovering and reporting the flaw, which has been patched in ARM 2026.2.1. SolarWinds makes no mention of the vulnerability being exploited in the wild.

    Cybersecurity

    The development comes nearly two months after the company shipped fixes for a critical flaw impacting Web Help Desk (WHD) (CVE-2026-28323, CVSS score: 9.8) that could result in a SAML authentication bypass when the SAML 2.0 authentication method is enabled.

    Another vulnerability relates to a denial-of-service (DoS) vulnerability (CVE-2026-28299, CVSS score: 8.2) that could cause the Web Help Desk server to crash due to insufficient memory. Both issues have been resolved in WHD 2026.2.1.

    SolarWinds has also released fixes for 16 flaws impacting Serv-U (CVE-2026-28302, from CVE-2026-28304 through CVE-2026-28317, CVE-2026-28321, CVE-2026-28323) that could lead to privilege escalation, remote code execution, and the creation of administrator accounts.

    arm Enabling Flaw HardCoded key Patches RCE SolarWinds unauthenticated
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild

    Identity Visibility in 2026: The Foundation of Identity Security

    Check Point, Kaspersky, Tanium Patch Product Vulnerabilities

    Viral AI actress’ hotline face-scans every caller, watches their mood

    North Korean WaterPlum hackers infected 30,000 devices worldwide

    BragJack attacks hijack AI browser agents through malicious extensions

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Cultural treasures are being destroyed by war, and people want justice

    September 20, 2026

    Meta’s Muse is creepy, but maybe not for the reasons you think

    September 20, 2026

    CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild

    September 20, 2026

    Gen Z are investing like Boomers

    September 20, 2026
    Latest Posts

    AIPAC Spending Dominates the Michigan Democratic Senate Primary

    August 5, 2026

    Labour members ‘have tougher view on welfare than you might think’, poll suggests | Labour

    August 5, 2026

    Palantir funnels earnings to US to avoid European taxes, report finds – POLITICO

    August 5, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Cultural treasures are being destroyed by war, and people want justice

    September 20, 2026

    Meta’s Muse is creepy, but maybe not for the reasons you think

    September 20, 2026

    CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild

    September 20, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.