On September 17, 2026, SolarWinds published a security advisory for CVE-2026-28326, a high-severity flaw in its Access Rights Manager (ARM) product caused by a hardcoded static cryptographic key. Under the right network conditions, the key lets an attacker with no credentials execute arbitrary code on the ARM server. SolarWinds rated it 8.8 out of 10 on CVSS 3.1 and shipped the fix in ARM 2026.2.1, which supersedes ARM 2026.2 and all earlier versions. SolarWinds credits Kai Huang of Armadin with reporting the bug, and at the time of disclosure The Hacker News reported no evidence of active exploitation in the wild.
What ARM does, and why a hardcoded key matters here
Access Rights Manager is an identity-governance product: it audits and manages who has access to what across Active Directory, file servers, Exchange, and SharePoint, and it's typically deployed with broad read/write privilege over those systems so it can report on and remediate access sprawl. That's exactly the kind of software you don't want an attacker to gain code execution on — a compromised ARM instance sits at a chokepoint for identity data across an organization.
The root cause, per SolarWinds' advisory and the CVE record (CWE-321, "use of hardcoded cryptographic key"), is that ARM shipped with a static key baked into the application rather than one generated per install. When a cryptographic key is the same across every deployment of a product, anyone who obtains a copy of the software — which for commercial products is trivial — can extract that key and use it to forge whatever the key was meant to protect (in ARM's case, apparently enough to reach unauthenticated remote code execution). This is a known-bad pattern; it's the same category of mistake that has hit other vendors' management appliances over the years, and it's avoidable with per-install key generation at setup time.
One nuance worth being precise about: the CVSS vector SolarWinds published is CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The AV:A component means the attack vector is "adjacent network," not "network" (AV:N). In plain terms, an attacker generally needs to already be on the same local network segment as the ARM server — not simply anywhere on the internet — to exploit this directly. That doesn't make it low-risk (no authentication and no user interaction are required, and the impact is full compromise: confidentiality, integrity, and availability all rated High), but it does mean internet-facing exposure isn't the primary threat model here the way it would be for an AV:N bug. The bigger risk is an attacker who has already landed somewhere on the internal network — via phishing, a VPN compromise, or a foothold on another machine — using this to pivot straight into identity infrastructure.
Part of a pattern, not an isolated incident
ARM is not the only SolarWinds product to need an urgent patch in 2026, and it's worth listing the run because the pattern matters more than any single CVE:
- CVE-2025-40551 — a Web Help Desk unauthenticated deserialization bug (CVSS 9.8), fixed in WHD 2026.1 in late January 2026 and added to CISA's Known Exploited Vulnerabilities catalog on February 3, 2026.
- CVE-2025-40538 through CVE-2025-40541 — four critical Serv-U vulnerabilities (CVSS 9.1, exploitable only with administrative privileges) patched in Serv-U 15.5.4 in February 2026.
- CVE-2026-28318 — a Serv-U denial-of-service flaw disclosed on June 3, 2026, which CISA added to its Known Exploited Vulnerabilities catalog on June 5, 2026.
- A batch of 15 critical (CVSS 9.1) Serv-U vulnerabilities — covering privilege escalation, account takeover, and root-level remote code execution — patched in Serv-U 2026.3 on July 21, 2026.
- Now CVE-2026-28326 in ARM, patched September 17, 2026.
Three product lines (Web Help Desk, Serv-U, and now ARM), several different root causes (deserialization, DoS via crafted requests, access-control and escalation bugs, and now a hardcoded key), within about nine months, at one vendor. Any one of these on its own would be a routine "patch your stuff" advisory. Taken together — many rated CVSS 9 or higher, and two on CISA's exploited list — they are a reasonable prompt to ask harder questions about a vendor's secure-development practices rather than put it down to bad luck on a single release.
What this changes
For a team running SolarWinds ARM: patch. There's no workaround short of upgrading to 2026.2.1 — a hardcoded key can't be rotated or configured away by the customer, since the whole point of the flaw is that it's baked into the shipped code. If your ARM instance sits on a network segment reachable by general users, contractors, or anything less trusted than your most sensitive tier, treat this with urgency even though it's not directly internet-exploitable.
For engineers who don't run SolarWinds products, the practical takeaway is about your own code, not theirs: search your own codebase for hardcoded secrets and static keys. If your product embeds any cryptographic key, API secret, or signing key in source rather than generating it per deployment or pulling it from a secrets manager at runtime, you have the same class of bug waiting for its own CVE. A secret-scanning step in CI that blocks merges on hardcoded-key patterns is the cheap, durable fix, and it's worth checking whether your team has one.
For anyone evaluating identity/access-management tooling, the pattern above is a legitimate input into vendor risk assessment — not because SolarWinds is uniquely bad, but because a product's incident history is one of the few signals you can check before you deploy it. Wise Hustlers reviews authentication and access-control code as part of its cybersecurity services, and this kind of hardcoded-credential defect is exactly the class of issue that pattern-based scanning and manual review during a security pass is meant to catch before it ships, not after a CVE is assigned.
There's no indication yet that CVE-2026-28326 is being exploited, and its adjacent-network requirement narrows who's immediately at risk. The thing worth watching is whether SolarWinds treats this as a one-off or whether more critical disclosures show up before the year is out — at that point it stops being a vulnerability story and becomes a vendor-trust story.
Sources
- SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE — The Hacker News
- CVE-2026-28326 — SolarWinds Trust Center security advisory
- CVE-2026-28326 — OpenCVE
- ARM 2026.2.1 release notes — SolarWinds documentation
- CISA: Patch actively exploited SolarWinds Serv-U DoS vulnerability (CVE-2026-28318) — Help Net Security
- SolarWinds Patches 15 Critical Serv-U Vulnerabilities Enabling Root Access — Security Online
- SolarWinds Patches Four Critical Serv-U Vulnerabilities — SecurityWeek