DIRAS TAKE
Act urgently: public exploit code exists for this flaw, so reduce exposure immediately and implement vendor guidance or network restrictions where possible.
What is CVE-2026-28326?
An unauthenticated attacker can execute arbitrary code against SolarWinds Access Rights Manager by abusing a hardcoded static key, tracked as CVE-2026-28326. The vulnerability affects Access Rights Manager 2026.2 and all previous 2026.x releases listed, and requires only adjacent-network access (no user interaction and no privileges). Successful exploitation can lead to full confidentiality, integrity, and availability loss on affected installs.
Vector CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of SolarWinds Access Rights Manager are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 2026.x | 2026.2 and all previous versions |
Is CVE-2026-28326 being exploited?
Public exploit code is available.
How to fix CVE-2026-28326
- Isolate Access Rights Manager instances from untrusted and adjacent networks and restrict access to trusted management subnets.
- Apply network-level controls (firewalls, VLANs) to limit exposure and require management access via VPN or jump hosts.
- Monitor logs and alerts for suspicious activity and attempts to use the static key or abnormal authentication behavior.
- Follow any vendor guidance from SolarWinds and prepare to deploy vendor-supplied patches when they become available.
Frequently asked questions
Is CVE-2026-28326 being actively exploited?
SolarWinds Access Rights Manager has public exploit code available, but there are no confirmed public reports of active exploitation as of 2026-09-29.
Which Access Rights Manager versions are affected by CVE-2026-28326?
Access Rights Manager 2026.2 and all previous 2026.x versions are listed as affected.
Is there a patch for CVE-2026-28326?
There are no fixed versions listed for this issue; administrators should follow vendor guidance and apply mitigations until a vendor patch is released.
Does CVE-2026-28326 require authentication?
No, CVE-2026-28326 is an unauthenticated vulnerability in SolarWinds Access Rights Manager and does not require valid credentials to exploit.
References
- nvd.nist.gov/vuln/detail/CVE-2026-28326
- cve.org/CVERecord?id=CVE-2026-28326
- solarwinds.com/trust-center/security-advisories/CVE-2026-28326
- documentation.solarwinds.com/en/success_center/whd/content/release_notes/arm_2026-2-1_release_notes.htm
- documentation.solarwinds.com/en/success_center/arm/content/secure-your-arm-deployment.htm
- All SolarWinds CVEs on CVE Radar
- CVEs published in September 2026