// 1 CRITICAL · 2 ZERO-DAY · 2 CVE IN THE LAST 24H→
SolarWinds released patch 2026.2.1 for Access Rights Manager. CVE-2026-28326 enables unauthenticated RCE via a hard-coded cryptographic key, with a CVSS score of 8.8.
{"main_topic":"cybersecurity","topics":["cybersecurity","vulnerability","cve","rce","patch"]}

SolarWinds released security updates for Access Rights Manager on September 17, 2026, addressing CVE-2026-28326, an unauthenticated remote code execution vulnerability caused by a hard-coded cryptographic key in the enterprise software. The flaw, classified as CWE-321 and rated 8.8 out of 10.0 on the CVSS:3.1 scale per the official NVD record, affects all ARM versions 2026.2 and earlier. The discovery by researcher Kai Huang of Armadin reignites the debate over secure development practices at a vendor that already weathered the SUNBURST crisis in 2020.

Key Takeaways
  • CVE-2026-28326 affects SolarWinds Access Rights Manager 2026.2 and earlier; the patch is available in version 2026.2.1
  • The CVSS:3.1 score is 8.8 HIGH with vector AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating complete impact on confidentiality, integrity, and availability
  • The root cause is a static hard-coded cryptographic key in the code, classified as CWE-321; the attack vector requires adjacent network position but no credentials or user interaction
  • SolarWinds does not mention in-the-wild exploitation in its September 17, 2026 advisory; researcher Kai Huang of Armadin is credited for the report
"SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability. The issue stems from a hard-coded static key." — SolarWinds Advisory, reported by The Hacker News

The Mechanism: Why a Hard-Coded Key Is a Deterministic Bypass

The vulnerability falls under CWE-321: Use of Hard-coded Cryptographic Key. This architectural defect pattern is well documented in software security literature: when a cryptographic key is statically embedded in the binary or source code, any attacker able to extract it or learn its value — through reverse engineering, accidental leaks, or repository access — gains cryptographic capability equivalent to that of the legitimate system.

According to the NVD record, the CVSS:3.1 vector AV:A (Attack Vector: Adjacent) indicates the attacker must be on the same adjacent network as the target. However, required privileges are none (PR:N) and user interaction is none (UI:N). This combination means that once network position is achieved, the exploit encounters no further access controls. Impact is maximum across the three security pillars: confidentiality, integrity, and availability (C:H/I:H/A:H).

The dossier does not specify the full technical chain linking the hard-coded key to arbitrary code execution. No source documents the parsing mechanism, the vulnerable function, or any race conditions. This gap prevents assessing exploit complexity and estimating the likelihood of public proof-of-concept emergence.

Comparison with SUNBURST: The Same Company, a Different Response

The 2020 SUNBURST incident left a deep mark on SolarWinds. A supply-chain attack compromised Orion updates, impacting roughly 18,000 customers and leading to the selective compromise of high-profile targets. The handling of that crisis drew criticism for slow communication and detection.

Compared to 2020, the response to CVE-2026-28326 shows different characteristics: an advisory released the same day as the news publication, a CVE identifier assigned and tracked, an external researcher explicitly credited, and a patch available concurrently with disclosure. This operational profile aligns more closely with current responsible disclosure best practices than the SUNBURST handling. However, the substance of the defect — a hard-coded cryptographic key in an enterprise product in 2026 — raises questions about the maturity of the internal secure development lifecycle.

The persistence of this pattern in an IT security vendor is particularly problematic because Access Rights Manager is a privilege governance tool. The product manages accounts, permissions, and access in Active Directory and hybrid cloud environments; a compromise at this level expands the attack perimeter laterally, subverting the very control the software is meant to enforce.

What to Do Now

Organizations using SolarWinds Access Rights Manager must verify the installed version and plan the upgrade to 2026.2.1. The AV:A vector reduces exposure compared to a public-facing network vulnerability, but does not eliminate risk in environments with already-compromised lateral access — a common scenario in multi-stage intrusions.

It is advisable to ensure ARM instances are not reachable from unauthorized network segments, given that the attack vector requires only topological adjacency. Sources do not document alternative temporary countermeasures to the patch; neither SolarWinds nor the cited technical sources provide guidance on potential workarounds or compensating mitigations.

Threat intelligence teams should monitor for proof-of-concept publication or signs of exploitation. At present, no source reports in-the-wild exploits, but the deterministically bypassable nature of a hard-coded key makes the vulnerability attractive to exploit developers once reverse-engineered.

Security audits of SolarWinds products must integrate verification of this update into priority patch management cycles, considering the CVSS 8.8 and the functional criticality of the product in privilege management.

The Systemic Problem of Hard-Coded Keys in 2026

The discovery of CWE-321 in a mature enterprise product is not an isolated case. The practice of embedding cryptographic keys in source code persists despite being classified as a critical defect for over a decade. Reasons include development convenience, automated tests that depend on predictable values, and legacy architectures never redesigned for secure secret management.

What makes CVE-2026-28326 relevant beyond the single case is the convergence of three factors: a vendor with a supply-chain compromise history, a security product governing elevated privileges, and an elementary architectural defect that turns static knowledge into remote execution capability. This triad amplifies potential damage compared to the same vulnerability in a less sensitive context.

The NVD record classifies the defect as CWE-321; OffSeq corroborated this classification in its technical radar. Strix.ai, a security vendor and CNA, independently confirmed the core case data. The convergence of primary sources on such a basic mechanism suggests the problem lies not in the vulnerability's complexity, but in its banality — which, for defenders, is even more concerning.

Frequently Asked Questions

Can CVE-2026-28326 be exploited from the Internet?
No, per the official NVD CVSS:3.1 vector the attack vector is AV:A (Adjacent), not AV:N (Network). The attacker must be on the same adjacent network as the target system. This limitation does not preclude danger in internal compromise scenarios or access to nearby network segments.

Why does a hard-coded key enable RCE rather than just decryption?
The dossier does not document the full exploit chain. The hard-coded key could be used to sign tokens, bypass authentication, or decrypt payloads that then trigger execution; the specific mechanism is not described in available sources.

Did SolarWinds handle this disclosure differently than SUNBURST?
Yes: the patch was released concurrently with the advisory, the researcher was credited, and the CVE was formally tracked. This profile is more transparent than the 2020 handling, though the architectural defect reveals weaknesses in the secure development lifecycle.

Information has been verified against cited sources and is current as of publication.

Sources


Sources and references
  1. thehackernews.com
  2. guardianmssp.com
  3. blog.netmanageit.com
  4. radar.offseq.com
  5. strix.ai
  6. nvd.nist.gov