SolarWinds disclosed CVE-2026-28326, an unauthenticated remote code execution vulnerability in SolarWinds Access Rights Manager (ARM). An attacker could potentially execute code on affected systems without first authenticating. The flaw affects ARM releases earlier than version 2026.2.
SolarWinds issued guidance for the vulnerability, and the Canadian Centre for Cyber Security and Guyana National CIRT urged administrators to review the advisory and apply the available update. The referenced advisories do not report exploitation of CVE-2026-28326 in the wild.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
The Canadian Centre for Cyber Security published advisory AV26-941 for CVE-2026-28326 and urged users and administrators to review the guidance and apply necessary updates.
SolarWinds disclosed CVE-2026-28326, an unauthenticated remote code execution vulnerability affecting Access Rights Manager versions before 2026.2. Updating to version 2026.2 or later was identified as the remediation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcecyber.gc.ca
Open sourcecirt.gy
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.