Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: hardcoded-key (3 articles)Clear

SolarWinds Access Rights Manager hard coded key enables unauthenticated remote code execution

SolarWinds patched a high-severity flaw in Access Rights Manager, tracked as CVE-2026-28326 and rated 8.8, that stems from a hard-coded static key and can lead to unauthenticated remote code execution. The issue affects all Access Rights Manager 2026.2 and prior releases and is fixed in 2026.2.1. SolarWinds credited Armadin researcher Kai Huang and reported no evidence of exploitation in the wild. The advisory arrives alongside separate fixes: a Web Help Desk SAML authentication bypass, a Web Help Desk denial-of-service issue, and sixteen Serv-U flaws that could allow privilege escalation, code execution, and creation of administrator accounts.

Check
Inventory SolarWinds Access Rights Manager instances, confirm versions at or below 2026.2, and upgrade to 2026.2.1 on an emergency schedule.
Affected
Access Rights Manager 2026.2 and earlier ship a hard-coded static key that an unauthenticated attacker can use to reach remote code execution.
Fix
Patch to 2026.2.1, restrict management interfaces to trusted networks, and separately update Web Help Desk and Serv-U to their fixed builds.

Exploited Issabel PBX flaw uses a shared hardcoded key to run commands unauthenticated

Attackers are exploiting a critical flaw in Issabel Framework, the web interface for the open-source Asterisk-based phone system. Tracked as CVE-2026-89026 and scored 9.8, the flaw stems from a hardcoded token-signing key that is identical across every installation, so an unauthenticated attacker can forge a valid access token, call the system's call-origination endpoint, and make Asterisk run arbitrary operating-system commands. Researchers at VulnCheck flagged it, and the Shadowserver Foundation first saw exploitation on September 9. A patch released on August 1 replaces the shared key with a unique per-installation key. Exposed, unpatched phone systems should be treated as urgent given the low barrier to attack.

Check
Update Issabel Framework to the patched version that replaces the shared signing key, and take the phone system's web interface off the public internet, restricting it to trusted management networks.
Affected
Organizations running internet-exposed Issabel Framework phone systems (CVE-2026-89026); because the signing key is identical everywhere, an unauthenticated attacker can forge a token and run operating-system commands, and exploitation is underway.
Fix
Patch to remove the hardcoded key, restrict and monitor access to the PBX web and management interfaces, hunt for forged-token requests and unexpected command execution, and rotate credentials if compromise is suspected.

Acer Wave 7 mesh routers: max-severity zero-days CVE-2026-49200/49201 expose plaintext credentials and hardcoded AES backdoor key, patch end of June

Acer is working to patch two maximum-severity zero-days in its Wave 7 mesh routers running firmware T7c_GBL_1.01.000055 or earlier, reported by researcher Gergo Pap. CVE-2026-49200 is a broken-access-control flaw: the acer_cgi.log file is reachable without authentication via the web interface and contains cleartext web and Telnet login credentials, leading to unauthorized system access. CVE-2026-49201 stems from a hardcoded AES key in the upload.cgi backup-processing binary, letting unauthenticated remote attackers decrypt, modify, and re-encrypt system backups to inject a persistent backdoor. No patches are available yet; Acer targets fixes by the end of June 2026 and urges users to update immediately once released.

Check
Inventory Acer Wave 7 mesh routers and confirm firmware version. Restrict web-interface and Telnet access to trusted networks. Watch for Acer's end-of-June firmware and apply immediately on release.
Affected
Acer Wave 7 routers on firmware T7c_GBL_1.01.000055 or earlier. CVE-2026-49200 exposes cleartext credentials in an unauthenticated log file; CVE-2026-49201's hardcoded AES key enables backdoored backups.
Fix
No patch yet (targeted end of June 2026). Disable remote/WAN management, restrict admin access to wired LAN, and rotate router and Telnet credentials. Apply Acer firmware the moment it ships.