CERT-FR flags SolarWinds ARM RCE flaw
CERT-FR advisory warns of a remote code execution vulnerability in SolarWinds Access Rights Manager versions prior to 2026.2.1.
CERT-FR issued an advisory covering CVE-2026-28326, a vulnerability in SolarWinds Access Rights Manager (ARM) that allows an attacker to achieve remote arbitrary code execution. All versions prior to 2026.2.1 are affected. The advisory does not indicate active exploitation in the wild; it is a standard vendor-patch notification relayed by the French CERT.
Defenders running SolarWinds ARM should consult the vendor's security bulletin and upgrade to version 2026.2.1 or later as soon as possible. No indicators of compromise, exploit details, or attacker attribution are provided in this bulletin. Given the criticality of Access Rights Manager in enterprise identity and permissions management, organizations should prioritize patching and review external exposure of the ARM management interface.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1211
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free