SolarWinds patches a hard-coded key that opened remote code execution on Access Rights Manager
On September 17, 2026, SolarWinds shipped a fix for CVE-2026-28326, an unauthenticated remote code execution flaw in Access Rights Manager caused by a hard-coded static key. Apply 2026.2.1 immediately and audit your access-governance tooling for embedded secrets.