CVE-2026-28326: SolarWinds Access Rights Manager

High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.

SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability. The issue stems from a hardcoded static key.

Affected products

  • SolarWinds Access Rights Manager: up to and including 2026.2

Published 2026-09-17. Last modified 2026-09-18.