<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Access Rights Manager - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/access-rights-manager/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 17 Sep 2026 17:59:14 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/access-rights-manager/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Unauthenticated Remote Code Execution in SolarWinds Access Rights Manager</title><link>https://feed.craftedsignal.io/briefs/2026-09-solarwinds-arm-rce/</link><pubDate>Thu, 17 Sep 2026 17:59:14 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-solarwinds-arm-rce/</guid><description>CVE-2026-28326 is a critical remote code execution vulnerability in SolarWinds Access Rights Manager resulting from the use of a hardcoded static key, allowing unauthenticated attackers to execute arbitrary code.</description><content:encoded><![CDATA[<p>SolarWinds Access Rights Manager is affected by a critical remote code execution vulnerability, tracked as CVE-2026-28326. The vulnerability arises from the implementation of a hardcoded static cryptographic key within the application. This flaw enables an unauthenticated attacker to bypass authentication mechanisms and execute arbitrary code on the underlying host. Given that Access Rights Manager typically operates with high-privileged service accounts to manage directory and file permissions across an organization, successful exploitation poses a severe risk of full environment compromise. Organizations utilizing SolarWinds Access Rights Manager on Windows Server platforms are urged to review security advisories from SolarWinds for patch availability and mitigation guidance, as this vulnerability provides a direct pathway for initial access and execution without requiring valid credentials.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to achieve remote code execution on the target Windows Server hosting the Access Rights Manager software. Because the application manages sensitive access controls, compromised instances could lead to unauthorized privilege escalation, exfiltration of directory services data, and persistent access across the enterprise network.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the identification of all internet-facing or internal SolarWinds Access Rights Manager instances. Monitor for security updates provided by SolarWinds and apply patches as soon as they are released. Ensure that service accounts utilized by Access Rights Manager follow the principle of least privilege to contain potential blast radiuses.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>rce</category><category>windows</category></item></channel></rss>