CVE-2026-28326
SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability. The issue stems from
CVSS
8.8
Alto
EPSS
0.5%
p45
KEV
—
Exploit Today
13
0-100
Publicado: 17 sept 2026 · Última mod.: 18 sept 2026 · CWE-321
0.5%EPSS · 30 días0.5%
2026-09-182026-09-22
SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability. The issue stems from a hardcoded static key.
- documentation.solarwinds.comhttps://documentation.solarwinds.com/en/success_center/arm/content/secure-your-arm-deployment.htm
- documentation.solarwinds.comhttps://documentation.solarwinds.com/en/success_center/whd/content/release_notes/arm_2026-2-1_release_notes.htm
- www.solarwinds.comhttps://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28326
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-814788.1 ALT32.3%
——10Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Hard-coded Cryptographic Key vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.4dCVE-2026-50606—0.1%
——0A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. The vulnerability is caused by the use of a hard-coded AES encryption key within the software. Under certain circumstances, a local attacker may be able to use the embedded key to access protected information or perform unauthorized actions.4dCVE-2026-50603—0.1%
——0A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The vulnerability is caused by the use of a hard-coded AES encryption key within the software. Under certain circumstances, a local attacker may be able to use the embedded key to access protected information or perform unauthorized actions.4dCVE-2026-813265.5 MED2.4%
——1QND uses a hard-coded cryptographic key, which may allow a local attacker who is logged in to a Windows PC where the affected product's client is installed to obtain administrator credentials, including an ID and password.6dCVE-2026-818559.1 CRÍ40.9%
——12A hardcoded cryptographic client authentication key vulnerability exists in the robot testing framework component of Wärtsilä FOS-Onboard.4dCVE-2026-782259.0 CRÍ35.3%
——11A hardcoded cryptographic server key vulnerability exists in the deployer-ng Update Controller component of Wärtsilä FOS-Onboard.6d