# CERT-FR flags SolarWinds ARM RCE flaw

Published: 2026-09-22 · Severity: routine · Sectors: technology
Canonical: https://vorant.io/reports/06cc1705-50a5-5224-b16d-dde61ea76d1d/cert-fr-flags-solarwinds-arm-rce-flaw

> CERT-FR advisory warns of a remote code execution vulnerability in SolarWinds Access Rights Manager versions prior to 2026.2.1.

CERT-FR issued an advisory covering CVE-2026-28326, a vulnerability in SolarWinds Access Rights Manager (ARM) that allows an attacker to achieve remote arbitrary code execution. All versions prior to 2026.2.1 are affected. The advisory does not indicate active exploitation in the wild; it is a standard vendor-patch notification relayed by the French CERT.

Defenders running SolarWinds ARM should consult the vendor's security bulletin and upgrade to version 2026.2.1 or later as soon as possible. No indicators of compromise, exploit details, or attacker attribution are provided in this bulletin. Given the criticality of Access Rights Manager in enterprise identity and permissions management, organizations should prioritize patching and review external exposure of the ARM management interface.

## Mentioned in this report

- Vulnerabilities: CVE-2026-28326

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1211

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/06cc1705-50a5-5224-b16d-dde61ea76d1d/cert-fr-flags-solarwinds-arm-rce-flaw.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
