{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3asolarwindsaccess_rights_manager/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:solarwinds:access_rights_manager:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-28326"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Access Rights Manager"],"_cs_severities":["high"],"_cs_tags":["vulnerability","rce","windows"],"_cs_type":"advisory","_cs_vendors":["SolarWinds"],"content_html":"\u003cp\u003eSolarWinds Access Rights Manager is affected by a critical remote code execution vulnerability, tracked as CVE-2026-28326. The vulnerability arises from the implementation of a hardcoded static cryptographic key within the application. This flaw enables an unauthenticated attacker to bypass authentication mechanisms and execute arbitrary code on the underlying host. Given that Access Rights Manager typically operates with high-privileged service accounts to manage directory and file permissions across an organization, successful exploitation poses a severe risk of full environment compromise. Organizations utilizing SolarWinds Access Rights Manager on Windows Server platforms are urged to review security advisories from SolarWinds for patch availability and mitigation guidance, as this vulnerability provides a direct pathway for initial access and execution without requiring valid credentials.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to achieve remote code execution on the target Windows Server hosting the Access Rights Manager software. Because the application manages sensitive access controls, compromised instances could lead to unauthorized privilege escalation, exfiltration of directory services data, and persistent access across the enterprise network.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the identification of all internet-facing or internal SolarWinds Access Rights Manager instances. Monitor for security updates provided by SolarWinds and apply patches as soon as they are released. Ensure that service accounts utilized by Access Rights Manager follow the principle of least privilege to contain potential blast radiuses.\u003c/p\u003e\n","date_modified":"2026-09-17T17:59:14Z","date_published":"2026-09-17T17:59:14Z","id":"https://feed.craftedsignal.io/briefs/2026-09-solarwinds-arm-rce/","summary":"CVE-2026-28326 is a critical remote code execution vulnerability in SolarWinds Access Rights Manager resulting from the use of a hardcoded static key, allowing unauthenticated attackers to execute arbitrary code.","title":"Unauthenticated Remote Code Execution in SolarWinds Access Rights Manager","url":"https://feed.craftedsignal.io/briefs/2026-09-solarwinds-arm-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:solarwinds:access_rights_manager:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}