Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

SolarWinds Patches Critical ARM Vulnerability, Highlighting the Growing Need for Cybersecurity Awareness




SolarWinds has released critical security patches to address a severe vulnerability in their Access Rights Manager (ARM) software, which could lead to unauthenticated remote code execution. The vulnerability affects all versions of ARM 2026.2 and prior, making it a widespread concern for SolarWinds customers. The company has patched the issue in ARM 2026.2.1, but organizations are urged to prioritize cybersecurity awareness and implement robust security measures to protect against emerging threats.

  • SolarWinds has released critical security patches for Access Rights Manager (ARM) software to address a severe vulnerability rated 8.8/10.
  • The vulnerability allows an attacker to execute arbitrary code without authentication due to a hard-coded static key.
  • The issue affects all versions of ARM 2026.2 and prior.
  • SolarWinds has credited Armadin security researcher Kai Huang with discovering the flaw.
  • A second critical vulnerability has been patched in WHD software, with a CVSS score of 9.8.
  • 16 other vulnerabilities have been patched in Serv-U software, including privilege escalation and remote code execution.
  • Organizations must prioritize cybersecurity awareness and implement robust security measures to protect against such vulnerabilities.



  • SolarWinds, a prominent provider of network management and monitoring solutions, has recently released critical security patches to address a severe vulnerability in their Access Rights Manager (ARM) software. The vulnerability, tracked as CVE-2026-28326, is rated 8.8 out of 10.0 on the CVSS scoring system, making it a high-priority threat for organizations that rely on SolarWinds' products.

    The issue stems from a hard-coded static key, which allows an attacker to execute arbitrary code without authentication. This vulnerability affects all versions of Access Rights Manager 2026.2 and prior, making it a widespread concern for SolarWinds customers. The company has credited Armadin security researcher Kai Huang with discovering and reporting the flaw, which has since been patched in ARM 2026.2.1.

    This patching comes on the heels of another critical vulnerability in SolarWinds' Web Help Desk (WHD) software, which was addressed in CVE-2026-28323. The WHD vulnerability has a CVSS score of 9.8, making it one of the most severe vulnerabilities reported in recent months. The WHD vulnerability could result in a SAML authentication bypass when the SAML 2.0 authentication method is enabled.

    Furthermore, SolarWinds has also released fixes for 16 other vulnerabilities in their Serv-U software, which could lead to privilege escalation, remote code execution, and the creation of administrator accounts. These vulnerabilities have been patched in Serv-U 2026.2.1.

    The SolarWinds vulnerabilities highlight the growing need for cybersecurity awareness and best practices among organizations. The recent patching of these critical vulnerabilities demonstrates the importance of staying up-to-date with the latest security patches and monitoring for potential vulnerabilities.

    As organizations continue to rely on third-party software and solutions, it is essential to prioritize cybersecurity awareness and implement robust security measures to protect against such vulnerabilities. This includes regular software updates, employee training, and the use of threat intelligence tools to stay ahead of emerging threats.

    In conclusion, the recent patching of critical vulnerabilities in SolarWinds' software highlights the importance of cybersecurity awareness and best practices among organizations. As the threat landscape continues to evolve, it is essential to stay vigilant and prioritize cybersecurity measures to protect against emerging threats.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/SolarWinds-Patches-Critical-ARM-Vulnerability-Highlighting-the-Growing-Need-for-Cybersecurity-Awareness-ehn.shtml

  • https://thehackernews.com/2026/09/solarwinds-patches-arm-hard-coded-key.html


  • Published: Sat Sep 19 06:50:01 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us