SolarWinds Access Rights Manager (ARM) Systemic Deserialization RCE — 17 CVEs, 6 Unauth SYSTEM RCE, Access Control Paradox — Threadlinqs Intelligence
As of 2026-05-30, SolarWinds Access Rights Manager (ARM) Systemic Deserialization RCE — 17 CVEs, 6 Unauth SYSTEM RCE, Access Control Paradox is a critical-severity vulnerability threat attributed to a N/A-nexus actor, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 65 indicators of compromise.
Threat ID: TL-2026-0016 · Severity: CRITICAL · Status: ACTIVE · Category: VULNERABILITY
Attribution: N/A · EXPLOITATION
SolarWinds Access Rights Manager (ARM) contains a systemic pattern of critical deserialization, directory traversal, and remote code execution vulnerabilities — 16+ CVEs disclosed between May 2024 and
SolarWinds Access Rights Manager (ARM) is an enterprise tool for managing, auditing, and provisioning access rights across Active Directory, Exchange, SharePoint, file servers, and other Windows infrastructure. Organizations use ARM to answer critical compliance questions: 'Who has access to what?' and 'Who changed what permissions?' ARM sits at the CENTER of the access control infrastructure — it has read and write access to Active Directory permissions, file server ACLs, and group memberships across the entire organization.
**THE VULNERABILITY LANDSCAPE — 16+ CVEs IN 5 MONTHS:**
Between May and September 2024, SolarWinds disclosed 16+ vulnerabilities in ARM across three patch cycles, representing one of the densest vulnerability clusters for a single enterprise product:
**July 17, 2024 — ARM 2024.3 (Mega-Patch: 13 CVEs):**
1. **CVE-2024-28074** (CVSS 9.6, Critical) — Internal Deserialization RCE. BYPASS of a previous incomplete fix. An anonymous ZDI researcher found that controls implemented for an earlier deserialization vulnerability could be circumvented using a different exploitation method. This is the CORE vulnerability for TL-2026-0016: .NET deserialization of untrusted data enabling unauthenticated remote code execution.
2. **CVE-2024-23469** (CVSS 9.6, Critical) — Exposed Dangerous Method RCE. Allows unauthenticated user to perform actions with SYSTEM privileges. Discovered by Piotr Bazydlo (@chudypb) of ZDI.
3. **CVE-2024-23470** (CVSS 9.6, Critical) — UserScriptHumster Exposed Dangerous Method. Pre-authentication remote command execution — unauthenticated user can run arbitrary commands and executables.
4. **CVE-2024-23471** (CVSS 9.6, Critical) — CreateFile Directory Traversal RCE. Authenticated user can abuse SolarWinds service for remote code execution.
5. **CVE-2024-23466** (CVSS 9.6, Critical) — Directory Traversal RCE. Unauthenticated user can perform remote code execution.
6. **CVE-2024-23475** (CVSS 9.6, Critical) — Directory Traversal and Information Disclosure. Unauthenticated arbitrary file deletion and sensitive information leakage.
7. **CVE-2024-23472** (CVSS 9.6, Critical) — Directory Traversal Arbitrary File Deletion and Information Disclosure.
8. **CVE-2024-23467** (CVSS 9.6, Critical) — Directory Traversal and Information Disclosure enabling RCE.
9. **CVE-2024-23465** (CVSS 8.3, High) — ChangeHumster Exposed Dangerous Method Authentication Bypass.
10. **CVE-2024-28992** (CVSS 7.6, High) — Traversal and Information Disclosure.
11. **CVE-2024-28993** (CVSS 7.6, High) — Traversal and Information Disclosure.
12. **CVE-2024-23468** (CVSS 7.6, High) — Traversal and Information Disclosure.
13. **CVE-2024-23474** (CVSS 7.6, High) — deleteTransferFile Directory Traversal, Arbitrary File Deletion and Information Disclosure.
**May 9, 2024 — ARM 2023.2.4 Patch:**
14. **CVE-2024-28075** (CVSS 9.0, Critical) — Deserialization of Untrusted Data RCE. The ORIGINAL deserialization vulnerability that CVE-2024-28074 later bypassed.
15. **CVE-2024-23473** (CVSS 8.6, High) — Hard-Coded Credentials Authentication Bypass.
**September 12, 2024 — ARM 2024.3.1:**
16. **CVE-2024-28991** (CVSS 9.0, Critical) — Deserialization of Untrusted Data RCE. ANOTHER deserialization RCE after the two previous patches. Authenticated user can abuse the service for remote code execution. Discovered by Piotr Bazydlo (@chudypb) of ZDI.
17. **CVE-2024-28990** (CVSS 6.3, Medium) — Hardcoded Credentials Authentication Bypass.
**THE PATTERN — SYSTEMIC ARCHITECTURAL FAILURE:**
The ARM vulnerability cluster reveals SYSTEMIC problems, not isolated bugs:
1. **Deserialization is fundamentally broken**: Three separate deserialization RCE CVEs (CVE-2024-28075, CVE-2024-28074, CVE-2024-28991) across three patch cycles. The second was explicitly a bypass of the first fix. The vendor cannot eliminate the deserialization attack surface — it keeps resurfacing.
2. **Directory traversal is pervasive**: 7+ CVEs for directory traversal
Weaknesses (CWE)
CWE-88, CWE-287
Target sectors: Government, Financial Services, Healthcare, Technology, Critical Infrastructure, Defense, Education
Target regions: Global, North America, Europe
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 65 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-24061, T1591, T1190, T1059, T1059, T1203, T1098, T1136, T1078, T1068, T1078