VORANT. Threat Intelligence Sign in Get the full feed

CERT-FR flags SolarWinds ARM RCE flaw

routine vulnerability technology

CERT-FR advisory warns of a remote code execution vulnerability in SolarWinds Access Rights Manager versions prior to 2026.2.1.

CERT-FR issued an advisory covering CVE-2026-28326, a vulnerability in SolarWinds Access Rights Manager (ARM) that allows an attacker to achieve remote arbitrary code execution. All versions prior to 2026.2.1 are affected. The advisory does not indicate active exploitation in the wild; it is a standard vendor-patch notification relayed by the French CERT.

Defenders running SolarWinds ARM should consult the vendor's security bulletin and upgrade to version 2026.2.1 or later as soon as possible. No indicators of compromise, exploit details, or attacker attribution are provided in this bulletin. Given the criticality of Access Rights Manager in enterprise identity and permissions management, organizations should prioritize patching and review external exposure of the ARM management interface.

Mentioned in this report

Vulnerabilities CVE-2026-28326

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1211

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free