SolarWinds Access Rights Manager security update for CVE-2026-28326
Security Patch Release
Summary
Hide ▲
Show ▼
SolarWinds released security updates for Access Rights Manager (ARM) to fix CVE-2026-28326, a high-severity flaw that could enable unauthenticated remote code execution. The issue affects all versions of ARM 2026.2 and prior and is rated CVSS 8.8. SolarWinds patched the bug in ARM 2026.2.1 after the flaw was reported by Armadin researcher Kai Huang. SolarWinds said it has no evidence of in-the-wild exploitation.
Related Happenings
Adobe security patch release for CVE-2026-48362
Security Patch Release
H score43
First: 11.08.2026 19:50
Last: 11.08.2026 19:50
Sources 1
About this happening:
Adobe shipped a priority 1 update for ColdFusion that fixes 15 security defects, including flaws that could enable arbitrary code execution and application D...
Adobe security patch release for CVE-2026-48362
Security Patch ReleaseAbout this happening: Adobe shipped a priority 1 update for ColdFusion that fixes 15 security defects, including flaws that could enable arbitrary code execution and application D...
Arista VeloCloud Orchestrator security update for CVE-2026-16812
Security Patch Release
H score55
First: 28.07.2026 01:49
Last: 28.07.2026 01:49
Sources 1
About this happening:
Arista patched CVE-2026-16812, a maximum-severity 10.0 OS command injection flaw in on-premises VeloCloud Orchestrator (VCO), after confirming it is actively...
Arista VeloCloud Orchestrator security update for CVE-2026-16812
Security Patch ReleaseAbout this happening: Arista patched CVE-2026-16812, a maximum-severity 10.0 OS command injection flaw in on-premises VeloCloud Orchestrator (VCO), after confirming it is actively...
CISA KEV order for SolarWinds Serv-U CVE-2026-28318
Public Sector Action
H score50
First: 06.06.2026 11:14
Last: 06.06.2026 11:14
Sources 1
About this happening:
CISA added CVE-2026-28318 affecting SolarWinds Serv-U to the KEV catalog and ordered FCEB agencies to remediate it by June 19, 2026. The directive expands...
CISA KEV order for SolarWinds Serv-U CVE-2026-28318
Public Sector ActionAbout this happening: CISA added CVE-2026-28318 affecting SolarWinds Serv-U to the KEV catalog and ordered FCEB agencies to remediate it by June 19, 2026. The directive expands...
SolarWinds security patch release for CVE-2026-28318
Security Patch Release
H score82
First: 05.06.2026 22:15
Last: 05.06.2026 22:15
Sources 1
About this happening:
SolarWinds released Serv-U 15.5.4 Hotfix 1 for CVE-2026-28318, an actively exploited denial-of-service flaw that can crash exposed Serv-U servers. The update fixes...
SolarWinds security patch release for CVE-2026-28318
Security Patch ReleaseAbout this happening: SolarWinds released Serv-U 15.5.4 Hotfix 1 for CVE-2026-28318, an actively exploited denial-of-service flaw that can crash exposed Serv-U servers. The update fixes...
Oracle security patch release for CVE-2026-21992
Security Patch Release
H score44
First: 21.03.2026 12:24
Last: 21.03.2026 12:24
Sources 1
About this happening:
Oracle released security updates for CVE-2026-21992, a critical flaw in Identity Manager and Web Services Manager that could enable unauthenticated remote co...
Oracle security patch release for CVE-2026-21992
Security Patch ReleaseAbout this happening: Oracle released security updates for CVE-2026-21992, a critical flaw in Identity Manager and Web Services Manager that could enable unauthenticated remote co...
Timeline
-
19.09.2026 12:31 2 articles · 3h ago
SolarWinds releases ARM update for CVE-2026-28326
Initial DisclosureSolarWinds released security updates for Access Rights Manager (ARM) to fix CVE-2026-28326, a high-severity unauthenticated remote code execution flaw caused by a hard-coded static key. The issue affects all versions of ARM 2026.2 and prior, was rated CVSS 8.8, and was patched in ARM 2026.2.1 after Armadin researcher Kai Huang reported it; SolarWinds said it had no evidence of in-the-wild exploitation.
Show sources
- SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE — thehackernews.com — 19.09.2026 12:31
- SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE — thehackernews.com — 19.09.2026 12:31