Back Redpacketsecurity CVE Alert: CVE-2026-28326 – SolarWinds
SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability. The issue stems from a hardcoded static key.
**Risk verdict:** High-risk unauthenticated code execution requiring adjacent network access; prioritise urgently, although KEV, SSVC exploitation, PoC and EPSS status are not provided.
**Why this matters:** Successful exploitation could give an attacker control of the management server, enabling theft or manipulation of privileged account and group information. Realistic objectives include domain reconnaissance, credential access, persistence, ransomware staging and disruption of identity-management operations.
**Most likely attack path:** An attacker able to reach the service from the same network segment, or through a compromised internal host, would require no credentials or user interaction and could exploit the weakness with low complexity. Scope is unchanged, but compromise of the management server may provide a practical bridge to directory services, administrative systems and other sensitive internal assets.
**Who is most exposed:** Organisations running the platform on server or administration networks with broad connectivity, especially where it is reachable from user VLANs, remote-access segments or poorly segmented management infrastructure. Internet exposure would materially increase concern despite the adjacent-network classification.
Alert on unexpected processes, shells or child processes spawned by the management service.
Review inbound connections from workstation, VPN and untrusted network segments.
Hunt for new services, scheduled tasks, accounts or modified administrative files.
Correlate anomalous directory queries, privileged changes and outbound connections from the server.
Mitigation and prioritisation:
Upgrade to the vendor’s fixed release as soon as change control permits; treat as an emergency security update.
Restrict access to trusted administration subnets using firewalls and ACLs; remove internet exposure.
Isolate the server and rotate potentially exposed credentials if compromise is suspected.
Confirm KEV, SSVC, EPSS and PoC status before final queueing; their absence leaves exploitation likelihood uncertain.
A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.
If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
