SolarWinds patched a high-severity flaw in Access Rights Manager, tracked as CVE-2026-28326 and rated 8.8, that stems from a hard-coded static key and can lead to unauthenticated remote code execution. The issue affects all Access Rights Manager 2026.2 and prior releases and is fixed in 2026.2.1. SolarWinds credited Armadin researcher Kai Huang and reported no evidence of exploitation in the wild. The advisory arrives alongside separate fixes: a Web Help Desk SAML authentication bypass, a Web Help Desk denial-of-service issue, and sixteen Serv-U flaws that could allow privilege escalation, code execution, and creation of administrator accounts.