The breach isn’t the problem. The spread is. →Free Assessment

Executive Summary

CVE-2026-28326 is a critical unauthenticated remote code execution vulnerability in SolarWinds Access Rights Manager (ARM) that allows attackers to gain NT AUTHORITY\SYSTEM privileges. The flaw stems from a hardcoded authentication key shipped with every installation, enabling attackers who can reach TCP port 55555 to bypass authentication and exploit .NET deserialization vulnerabilities. Given ARM's role in managing identity governance across Active Directory, file servers, and Exchange systems, successful exploitation provides attackers with extensive access to organizational assets. SolarWinds fixed the vulnerability in version 2026.2.1.7 by removing the vulnerable authentication fallback entirely.

This incident highlights the growing threat to identity governance platforms, which have become high-value targets due to their privileged access across enterprise environments. As organizations increasingly adopt zero-trust architectures, securing identity management infrastructure becomes critical to preventing supply chain compromises.

Why This Matters Now

Identity governance platforms like ARM are becoming prime targets for sophisticated threat actors seeking to compromise entire enterprise environments. The hardcoded authentication bypass demonstrates how supply chain vulnerabilities can provide immediate system-level access to critical infrastructure managing organizational permissions.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The vulnerability uses a hardcoded authentication key shipped with every ARM installation, allowing attackers to forge valid authentication tokens and bypass security controls on TCP port 55555.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would be highly relevant to this SolarWinds ARM compromise as it could have constrained the attacker's lateral movement through segmented network access and reduced the blast radius across the identity infrastructure.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Network segmentation policies would likely have limited the attacker's ability to reach the SolarWinds ARM server from untrusted network zones, potentially constraining access to the vulnerable TCP port 55555 service through microsegmentation controls.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Workload-level segmentation would likely have constrained the attacker's ability to leverage ARM's delegated credentials across multiple identity systems, reducing the scope of privilege escalation from the compromised ARM server to connected infrastructure.

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-west traffic inspection and microsegmentation would likely have limited the attacker's lateral movement pathways between ARM and target systems, constraining their ability to pivot freely through the Active Directory infrastructure using compromised credentials.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Network visibility and behavioral monitoring would likely have detected anomalous outbound communication patterns from the compromised ARM server, potentially constraining the attacker's ability to maintain persistent command and control channels through legitimate network paths.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Egress filtering and data loss prevention controls would likely have constrained the attacker's ability to exfiltrate large volumes of identity governance data, reducing the scope of sensitive information that could be transmitted to external command and control infrastructure.

Impact (Mitigations)

While Zero Trust segmentation would likely limit the scope of identity manipulation, attackers could still modify permissions within the directly compromised ARM system, though their ability to propagate changes across the broader identity fabric would be significantly constrained.

Impact at a Glance

Affected Business Functions

  • Identity and Access Management
  • Active Directory Administration
  • File Server Permission Management
  • Exchange and SharePoint Access Control
Operational Disruption

Estimated downtime: 3 days

Financial Impact

Estimated loss: N/A

Data Exposure

Complete compromise of identity governance system with potential access to all managed file servers, mailboxes, and user accounts across the enterprise. Attacker gains NT AUTHORITY\SYSTEM privileges on ARM servers with delegated administrative rights.

Recommended Actions

  • • Implement Zero Trust Segmentation to isolate identity governance systems like ARM from general network access, restricting TCP 55555 to only authorized components through microsegmentation policies
  • • Deploy Egress Security & Policy Enforcement to detect and block unauthorized outbound communications from compromised identity management systems, preventing command and control establishment
  • • Enable Multicloud Visibility & Control to monitor anomalous interactions with identity governance platforms and detect suspicious automation or repeated malformed requests against critical services
  • • Strengthen East-West Traffic Security to prevent lateral movement from compromised identity systems to Active Directory, file servers, and Exchange through workload-to-workload traffic inspection
  • • Implement Inline IPS (Suricata) to detect and block known exploit patterns targeting identity management vulnerabilities like CVE-2026-28326 through signature-based detection of malicious payloads

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image