A hardcoded authentication secret ships with every SolarWinds Access Rights Manager install, and reaching TCP 55555 is enough to hit a .NET deserialization sink. Bishop Fox confirmed SYSTEM-level code execution, breaks down the root cause, and shares a safe detection tool for defenders.
Master Key Included: Detecting SolarWinds ARM CVE-2026-28326
About this summary. This is a short, independently written summary of an article first published by Bishop Fox. Cyber Security News did not report or verify the underlying story. Read the original: https://bishopfox.com/blog/detecting-solarwinds-arm-cve-2026-28326

Source attribution: headline and facts are from Bishop Fox (bishopfox.com). Summary method: excerpt of the source description. See our source attribution policy.






