Redpacketsecurity Critical CVE-2026-28326 Vulnerability in SolarWinds Access Rights Manager
Article Content
- •CVE-2026-28326 allows unauthenticated remote code execution via a hardcoded key.
- •Organizations with broad connectivity and internet exposure are most vulnerable.
- •A patch (version 2026.2.1) is available; urgent upgrade is recommended.
SolarWinds Access Rights Manager has been identified with a high-risk unauthenticated remote code execution vulnerability (CVE-2026-28326) due to a hardcoded static key. This vulnerability allows attackers with adjacent network access to exploit the system without needing credentials or user interaction. Successful exploitation could lead to control over the management server, allowing for theft or manipulation of sensitive information, including privileged accounts. Organizations with broad connectivity, especially those exposing the service to the internet or poorly segmented networks, are particularly at risk. The vulnerability was published on September 17, 2026, and a fixed version (2026.2.1) is available. Immediate action is recommended to mitigate potential risks, including restricting access and upgrading to the patched version.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track CVE-2026-28326 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…