Skip to content
Critical CVE-2026-28326 Vulnerability in SolarWinds Access Rights Manager

Critical CVE-2026-28326 Vulnerability in SolarWinds Access Rights Manager

First seen 18 Sep 2026, 01:22 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 18, 2026 at 02:00 UTC
  • CVE-2026-28326 allows unauthenticated remote code execution via a hardcoded key.
  • Organizations with broad connectivity and internet exposure are most vulnerable.
  • A patch (version 2026.2.1) is available; urgent upgrade is recommended.

SolarWinds Access Rights Manager has been identified with a high-risk unauthenticated remote code execution vulnerability (CVE-2026-28326) due to a hardcoded static key. This vulnerability allows attackers with adjacent network access to exploit the system without needing credentials or user interaction. Successful exploitation could lead to control over the management server, allowing for theft or manipulation of sensitive information, including privileged accounts. Organizations with broad connectivity, especially those exposing the service to the internet or poorly segmented networks, are particularly at risk. The vulnerability was published on September 17, 2026, and a fixed version (2026.2.1) is available. Immediate action is recommended to mitigate potential risks, including restricting access and upgrading to the patched version.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-17
CVE-2026-28326 published
SolarWinds disclosed a high-risk unauthenticated remote code execution vulnerability in Access Rights Manager.
www.solarwinds.com
2026-09-18
CVE-2026-28326 reported
Redpacketsecurity reported on the vulnerability's implications and recommended urgent action for affected organizations.
Redpacketsecurity

More articles in this cluster (3)

Following this threat?

Track CVE-2026-28326 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed