SolarWinds Access Rights Manager Hard-Coded Cryptographic Key (CVE-2026-28326) Enables Unauthenticated RCE
SolarWinds Access Rights Manager Hard-Coded Cryptographic (TL-2026-2585) is a high-severity software vulnerability scored CVSS 8.8, first published 2026-09-19. It has no confirmed attribution, affects SolarWinds Access Rights Manager, references 1 CVE (CVE-2026-28326), maps to 8 MITRE ATT&CK techniques (T1005, T1059, T1069), and is covered by 9 detection rules and 14 indicators of compromise.
Key facts for TL-2026-2585
- Threat ID
- TL-2026-2585
- Severity
- HIGH
- CVSS
- 8.8 (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- 2026-09-19
- Last reviewed
- 2026-09-19
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Detection rules
- 9
- Indicators of compromise
- 14
SolarWinds patched CVE-2026-28326 (CVSS 3.1: 8.8), a hard-coded static cryptographic key (CWE-321) in Access Rights Manager (ARM) 2026.2 and prior that lets an unauthenticated attacker on the adjacent network achieve remote code execution. The fix ships in ARM 2026.2.1; SolarWinds reports no evidence of in-the-wild exploitation, no public PoC exists, and the CVE is absent from the CISA KEV catalog.
How SolarWinds Access Rights Manager Hard-Coded Cryptographic works
On September 17, 2026, SolarWinds published a security advisory and release notes for Access Rights Manager (ARM) 2026.2.1, fixing CVE-2026-28326, a high-severity (CVSS 3.1: 8.8, vector AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) vulnerability classified CWE-321 (Use of a Hard-coded Cryptographic Key). ARM is SolarWinds' Active Directory / Exchange / NTFS privileged-access-governance product. Multiple independently corroborating sources (SolarWinds' own advisory, NVD/OpenCVE, and third-party CVE trackers) consistently describe the root cause as a hardcoded static key embedded in the ARM application that permits an unauthenticated attacker to achieve remote code execution; none of the reviewed sources published the precise low-level exploitation mechanic (e.g., whether the key is used to sign, encrypt, or authenticate a message ARM's server subsequently trusts and processes), so that detail should be treated as vendor-undisclosed rather than assumed.
The attack vector is rated Adjacent Network (AV:A) rather than Network (AV:N), consistent with SolarWinds' own ARM deployment guidance, which documents ARM's internal server-to-collector and client communication and recommends ARM run on a dedicated, non-internet-facing server, with ARM and the SolarWinds Platform installed on separate servers. An attacker with reachability to ARM's internal service ports — e.g., from an already-compromised host on the same segment or VLAN — is therefore the realistic exploitation scenario, not a direct internet-facing attack. CVE-2026-28326 was reserved on February 26, 2026, publicly disclosed September 17, 2026, and last updated in NVD/OpenCVE on September 18, 2026. FIRST.org EPSS data available at disclosure time scored the CVE at approximately 0.5% exploitation probability (roughly the 55th percentile of all scored CVEs) — consistent with SolarWinds' statement that it has seen no evidence of in-the-wild exploitation and with the absence of any public proof-of-concept exploit code as of this writing.
This is not the first time SolarWinds ARM has shipped with a hard-coded/static secret exposed in its architecture: in September 2024, SolarWinds patched CVE-2024-28990 (hard-coded RabbitMQ credentials permitting authentication bypass to the ARM RabbitMQ management console, CVSS 6.3) alongside CVE-2024-28991 (an authenticated insecure-deserialization RCE yielding SYSTEM-level code execution, CVSS 9.0 per the vendor / 9.9 per Trend Micro Zero Day Initiative, discovered by Piotr Bazydlo of ZDI) — both fixed together in ARM 2024.3.1. CVE-2026-28326 now represents the same class of weakness (embedded/static secret material undermining ARM's trust boundary) in a fully unauthenticated form, a meaningful regression from the 2024 fixes.
CVE-2026-28326 was disclosed as part of a broader SolarWinds September 2026 security update cycle; the same Hacker News report that surfaced ARM's flaw also references concurrent SolarWinds advisories affecting Web Help Desk (CVE-2026-28323, CVE-2026-28299) and 16 flaws across Serv-U (CVE-2026-28302, CVE-2026-28304 through CVE-2026-28317, CVE-2026-28321, CVE-2026-28323). Independent research corroborates that CVE-2026-28323 is a SAML 2.0 authentication-bypass flaw in Web Help Desk (a forged/relayed SAMLResponse to the SAML Assertion Consumer Service endpoint establishes a session without valid credentials) and that CVE-2026-28299 is an unauthenticated denial-of-service flaw in the same product; both were fixed in WHD 2026.2.1. These are separate CVEs in separate SolarWinds products from CVE-2026-28326 and are not themselves mapped into this threat's MITRE/IOC data, but they establish that SolarWinds' privileged-IT-management product line underwent a coordinated multi-product patch cycle in mid-to-late 2026, and that at least one sibling flaw in that cycle (CVE-2026-28318, a Serv-U unauthenticated DoS disclosed in June 2026) was subsequently added to the CISA Known Exploited Vulnerabilities catalog — underscoring that SolarWinds privileged-access and IT-management tooling has been an active target class in 2026, even though CVE-2026-28326 itself carries no confirmed-exploitation evidence.
No technical writeup or proof-of-concept exploit code from discoverer Kai Huang (Armadin) or any third party has been identified as of this writing, and CVE-2026-28326 does not appear in the CISA KEV catalog. Impact is nonetheless rated CRITICAL because of what ARM manages: successful RCE against the ARM server (which SolarWinds documentation indicates runs with SYSTEM-level privileges) would hand an attacker code execution on the system that holds delegated rights to provision, audit, and modify Active Directory, Exchange, and NTFS file-share access — a direct path to account manipulation, AD permission-group discovery, and collection of locally stored access-governance data, independent of whether the attacker pivots further.
MITRE ATT&CK techniques used in TL-2026-2585
Collection
Execution
T1059 Command and Scripting Interpreter
Discovery
T1069 Permission Groups Discovery; T1087 Account Discovery
Persistence
T1098 Account Manipulation; T1543 Create or Modify System Process
Privilege Escalation
T1484 Domain or Tenant Policy Modification
Credential Access
Affected products and versions in SolarWinds Access Rights Manager Hard-Coded Cryptographic
- SolarWinds — Access Rights Manager
Vulnerable versions: 2026.2; all versions prior to 2026.2
Fixed in: 2026.2.1
Remediation for SolarWinds Access Rights Manager Hard-Coded Cryptographic
Patches
- SolarWinds Access Rights Manager 2026.2.1
Immediate actions
- Upgrade all SolarWinds Access Rights Manager deployments to version 2026.2.1 or later immediately
- Restrict network access to ARM server/collector/client communication ports to trusted management hosts only via firewall/IP allowlisting
- Confirm ARM is not reachable from general user VLANs, guest networks, or the internet
- Verify ARM and the SolarWinds Platform are installed on separate servers per current vendor deployment requirements
Workarounds
- No official workaround was published; SolarWinds' advisory and release notes direct customers to upgrade to 2026.2.1
Longer-term hardening
- Deploy ARM on a dedicated server isolated from general enterprise network segments, per SolarWinds' own hardening guidance
- Rotate RabbitMQ and other ARM internal service credentials/certificates after upgrading
- Apply network segmentation that isolates privileged identity/access-management infrastructure (ARM, AD tier-0 assets) from standard user and server VLANs
- Monitor ARM server logs and adjacent-network traffic for anomalous connections to ARM management ports
- Track and patch sibling SolarWinds products (Web Help Desk, Serv-U) disclosed in the same September 2026 update cycle, since at least one related Serv-U flaw (CVE-2026-28318) was independently added to CISA KEV
CVEs associated with SolarWinds Access Rights Manager Hard-Coded Cryptographic
CVE-2026-28326
Weaknesses (CWE) in SolarWinds Access Rights Manager Hard-Coded Cryptographic
CWE-321
Timeline of SolarWinds Access Rights Manager Hard-Coded Cryptographic
- SolarWinds discloses and patches CVE-2024-28990 (hard-coded RabbitMQ credentials) and CVE-2024-28991 (insecure-deserialization RCE, discovered by Piotr Bazydlo of Trend Micro ZDI, CVSS 9.0/9.9) in ARM 2024.3.1 — the earlier instance of embedded-secret weaknesses in ARM's internal messaging architecture.
- CVE-2026-28326 is reserved in the CVE numbering system, ahead of public disclosure.
- SolarWinds discloses sibling denial-of-service flaws CVE-2026-28299 (Web Help Desk) and CVE-2026-28318 (Serv-U), part of the same vendor's broader 2026 IT-management-product patch cadence; the Canadian Centre for Cyber Security publishes advisory AV26-549.
- CISA adds the related SolarWinds Serv-U flaw CVE-2026-28318 to the Known Exploited Vulnerabilities catalog, confirming active exploitation of a sibling SolarWinds product in the same 2026 disclosure cycle (distinct from CVE-2026-28326, which is not KEV-listed).
- SolarWinds patches CVE-2026-28323, a SAML 2.0 authentication-bypass vulnerability in Web Help Desk, in WHD 2026.2.1 — another sibling flaw in the same product family disclosed in the months leading up to CVE-2026-28326.
- SolarWinds releases Access Rights Manager 2026.2.1, which fixes CVE-2026-28326 and six unrelated customer-reported bugs (Exchange Online mailbox rights display, Azure AD group membership sync, AD alert triggering, collector reconnection, Exchange Online API rate-limit handling, and Configuration Wizard load times); the release notes state no new features were added.
- SolarWinds publishes a security advisory disclosing CVE-2026-28326, a hard-coded static cryptographic key in Access Rights Manager, crediting Armadin researcher Kai Huang for discovery and reporting.
- NVD and OpenCVE record CVE-2026-28326 with CVSS v3.1 vector AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (base score 8.8), CWE-321 classification, and an EPSS score of roughly 0.5% (55th percentile).
- CVE-2026-28326 is confirmed absent from the CISA Known Exploited Vulnerabilities (KEV) catalog as of this date.
- The Hacker News publishes coverage of CVE-2026-28326 alongside concurrent SolarWinds Web Help Desk (CVE-2026-28323, CVE-2026-28299) and Serv-U (16 flaws) advisories, noting SolarWinds reports no evidence of in-the-wild exploitation and that no public proof-of-concept exploit exists for CVE-2026-28326.
Sources cited for SolarWinds Access Rights Manager Hard-Coded Cryptographic
- SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE
- SolarWinds Security Advisory: CVE-2026-28326
- NVD - CVE-2026-28326 Detail
- CVE-2026-28326 - Vulnerability Details
- SolarWinds Access Rights Manager 2026.2.1 Release Notes
- Secure Your ARM Deployment
- CVE-2026-28326: CWE-321 Use of Hard-coded Cryptographic Key in SolarWinds Access Rights Manager
- CVE-2026-28326 Vulnerability Analysis
- Recommendations for CVE-2026-28323 and CVE-2026-28299
- SolarWinds Fixed Critical RCE CVE-2024-28991 in Access Rights Manager
- SolarWinds Issues Patch for Critical ARM Vulnerability Enabling RCE Attacks
- SolarWinds Patches Critical Vulnerability in Access Rights Manager (CVE-2024-28990/CVE-2024-28991 precedent coverage)
More in vulnerability
- Click2Shell WordPress Exploit Chain Lets Attackers Gain RCE With a Single Malicious Link
- CISA Flags Three Actively Exploited Linux Kernel Vulnerabilities: kTLS Receive-Path Disclosure/DoS, ebtables SNAT Privilege Escalation, and AF_ALG Race Condition (CVE-2025-39682, CVE-2026-53266, CVE-2025-39964)
- Critical Pre-Auth RCE in Orkes Conductor Workflow Platform (CVE-2026-58138) Exploited in the Wild
- "LPE Quartet": Public Exploits Released for Four Linux Kernel Local-Root Flaws (DirtyAH6, TUNderflow, PPPoEject, DiagSpill)
- CVE-2025-39682 — Linux Kernel net/tls rx_list Zero-Length Record Use-After-Free Added to CISA KEV Catalog
Detection coverage for TL-2026-2585
As of 2026-09-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2585 across Splunk SPL, Microsoft KQL and Sigma, covering 14 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.