Search

Find merged stories by title or summary.

DFIR
Emerging1 src

InfoSec News Nuggets – 09/22/2026

SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE SolarWinds has shipped security updates for Access Rights Manager after discovering a hard-coded static cryptographic key that could let an attacker execute code on a managed host without authentication. Tracked as CVE-2026-28326 with a CVSS score of 8. 8, the flaw affects all ARM versions 2026. 2 and earlier and was privately reported by a security researcher rather than found through active exploitation. Administrators are urged to upgrade to ARM 2026. 2. 1, which also resolves a batch of other recently disclosed flaws in the company’s Web Help Desk and Serv-U products.

·AboutDFIR
Read →
Vulnerabilities & Patches
Emerging1 src

SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE

SolarWinds has released security updates to address a high-severity flaw in Access Rights Manager (ARM) that, if successfully exploited, could lead to an unauthenticated remote code execution vulnerability. The vulnerability, tracked as CVE-2026-28326, is rated 8. 8 out of 10. 0 on the CVSS scoring system. The issue affects all versions of Access Rights Manager 2026. 2 and prior. "SolarWinds

·The Hacker News
Read →
Vulnerabilities & Patches
Emerging1 src

SolarWinds security advisory (AV26-941)

Serial number: AV26-941 Date: September 18, 2026 As of September 17, 2026, SolarWinds is affected by a vulnerability in the following product: • SolarWinds Access Rights Manager • Prior to 2026.2 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. • SolarWinds Access Rights Manager Unauthenticated Remote Code Execution Vulnerability (CVE-2026-28326) SolarWinds security advisory (AV26-941) - Canadian Centre for Cyber Security

·Malware.news
Read →

You've reached the end of current stories for this search.