← Back to feed
DFIREmerging1 sourceSep 22, 2026 · 10:08via AboutDFIR

InfoSec News Nuggets – 09/22/2026

Brief

SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE

SolarWinds has shipped security updates for Access Rights Manager after discovering a hard-coded static cryptographic key that could let an attacker execute code on a managed host without authentication. Tracked as CVE-2026-28326 with a CVSS score of 8. 8, the flaw affects all ARM versions 2026. 2 and earlier and was privately reported by a security researcher rather than found through active exploitation.

Administrators are urged to upgrade to ARM 2026.

  • 1, which also resolves a batch of other recently disclosed flaws in the company’s Web Help Desk and Serv-U products.
Read more on AboutDFIR