Executive Summary
SolarWinds patched a critical vulnerability in Access Rights Manager (ARM) tracked as CVE-2026-28326, scoring 8.8 on CVSS. The flaw stems from a hard-coded static key that enables unauthenticated remote code execution across all ARM versions 2026.2 and prior. Discovered by Armadin security researcher Kai Huang, the vulnerability was addressed in ARM 2026.2.1 with no evidence of active exploitation in the wild. This incident adds to SolarWinds' recent security challenges, including fixes for Web Help Desk SAML bypass and Serv-U privilege escalation flaws.
This vulnerability highlights the persistent risk of hard-coded credentials in enterprise software, particularly as organizations face increased scrutiny following high-profile supply chain attacks and regulatory pressure for secure software development practices.
Why This Matters Now
Hard-coded credential vulnerabilities represent a fundamental security anti-pattern that enables complete system compromise without authentication, making this especially critical as organizations implement zero-trust architectures and face increasing regulatory requirements for secure software development.
Attack Path Analysis
Attackers exploited CVE-2026-28326, a hard-coded static key vulnerability in SolarWinds Access Rights Manager, to achieve unauthenticated remote code execution. This initial compromise allowed privilege escalation within the ARM system, followed by lateral movement to connected identity management infrastructure. Attackers established command and control channels through egress traffic, exfiltrated sensitive identity data and access rights information, and potentially impacted business operations by compromising identity governance systems.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers exploited CVE-2026-28326 hard-coded static key vulnerability in SolarWinds Access Rights Manager to achieve unauthenticated remote code execution
Related CVEs
CVE-2026-28326
CVSS 8.8A hard-coded static key vulnerability in SolarWinds Access Rights Manager that could lead to unauthenticated remote code execution.
Affected Products:
SolarWinds Access Rights Manager – <= 2026.2
Exploit Status:
no public exploitCVE-2026-28323
CVSS 9.8A SAML authentication bypass vulnerability in SolarWinds Web Help Desk when SAML 2.0 authentication method is enabled.
Affected Products:
SolarWinds Web Help Desk – < 2026.2.1
Exploit Status:
no public exploitCVE-2026-28299
CVSS 7.5A denial-of-service vulnerability in SolarWinds Web Help Desk that could cause server crashes due to insufficient memory.
Affected Products:
SolarWinds Web Help Desk – < 2026.2.1
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
External Remote Services
Valid Accounts
Unsecured Credentials: Credentials In Files
Command and Scripting Interpreter
Exploitation for Privilege Escalation
Service Stop
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Configuration standards for system components
Control ID: 2.2.1
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.15
DORA – ICT Risk Management Framework
Control ID: Article 8
CISA ZTMM 2.0 – Identity and Access Management
Control ID: Function 2
NIS2 Directive – Cybersecurity risk-management measures
Control ID: Article 21(2)(a)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Information Technology/IT
Critical exposure via SolarWinds ARM hard-coded key vulnerability enabling unauthenticated RCE, requiring immediate patching across IT infrastructure management systems.
Government Administration
High risk from CVE-2026-28326 affecting identity and access management systems, with potential for privilege escalation and unauthorized administrative access.
Financial Services
Severe compliance violations possible through unauthenticated remote code execution bypassing NIST and PCI requirements for access rights management.
Health Care / Life Sciences
HIPAA compliance breaches likely from ARM vulnerability allowing unauthorized access to protected health information through compromised identity management systems.
Sources
- SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCEhttps://thehackernews.com/2026/09/solarwinds-patches-arm-hard-coded-key.htmlVerified
- SolarWinds Security Advisorieshttps://www.solarwinds.com/trust-center/security-advisoriesVerified
- SolarWinds ARM 2026.2.1 Release Noteshttps://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2026-2-1_release_notes.htmVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely have constrained this SolarWinds ARM attack by reducing lateral movement reach and limiting blast radius through network segmentation and egress controls. The fabric's identity-aware routing and east-west traffic enforcement could have reduced the attacker's ability to expand access across connected identity infrastructure.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The initial compromise of the ARM system would likely still occur, but the fabric's visibility and control mechanisms could limit the attacker's ability to establish persistent foothold across cloud environments
Control: Zero Trust Segmentation
Mitigation: Privilege escalation attempts would likely encounter segmented network boundaries that could reduce the attacker's ability to access higher-privileged identity management systems and governance functions
Control: East-West Traffic Security
Mitigation: Lateral movement between identity systems would likely be constrained by east-west traffic inspection and policy enforcement, reducing the attacker's reachability to connected Active Directory and cloud identity providers
Control: Multicloud Visibility & Control
Mitigation: Command and control channel establishment may be constrained through enhanced visibility across multi-cloud environments, potentially limiting the attacker's ability to maintain persistent communications across diverse infrastructure
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration attempts would likely encounter egress security controls that could reduce the volume and scope of sensitive identity data and credential information successfully transmitted to external destinations
While identity governance systems may still experience some compromise, the overall business impact would likely be reduced through contained blast radius and limited cross-system access propagation
Impact at a Glance
Affected Business Functions
- Identity and Access Management
- IT Security Operations
- Help Desk Services
- File Transfer Services
Estimated downtime: 1 days
Estimated loss: N/A
Potential unauthorized access to privileged systems and sensitive data managed by Access Rights Manager, Web Help Desk user credentials, and file transfer logs
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to isolate identity management systems and prevent lateral movement from compromised ARM systems to connected infrastructure
- • Deploy Egress Security & Policy Enforcement to detect and block unauthorized data exfiltration of identity information through compromised systems
- • Enable Multicloud Visibility & Control to monitor anomalous interactions with identity systems and detect suspicious automation patterns
- • Implement Inline IPS (Suricata) to identify and block known exploit patterns targeting identity management vulnerabilities like CVE-2026-28326
- • Deploy Cloud Native Security Fabric (CNSF) with real-time inspection capabilities to provide autonomous protection against unauthenticated remote code execution attempts



