Search

Find merged stories by title or summary.

Vulnerabilities & Patches
Emerging1 src

CISA Adds Four Known Exploited Vulnerabilities to Catalog

CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. • CVE-2026-75650 Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability • CVE-2026-81963 Microsoft Windows Link Following Vulnerability • CVE-2026-85880 Microsoft Windows Heap-Based Buffer Overflow Vulnerability • CVE-2026-86218 N-able N-central Static Code Injection Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies.

·CISA Alerts
Read →
Vulnerabilities & Patches
Emerging1 src

CVE-2026-86218 - N-able N-central Static Code Injection Vulnerability

N-able N-central contains a static code injection vulnerability that could allow for pre-authentication remote code execution.

·CISA KEV
Read →
Vulnerabilities & Patches
Emerging1 src

N-able Releases Hotfix for Critical Remote Code Execution Vulnerability

The vulnerability, CVE-2026-86218, was allocated a maximum-severity rating by the software provider itself

·Infosecurity Magazine
Read →
Vulnerabilities & Patches
Emerging1 src

N-able patches critical N-central zero-day exploited in the wild (CVE-2026-86218)

N-able released an emergency hotfix for CVE-2026-86218, a remote code execution (RCE) flaw affecting N-central, its remote monitoring and management (RMM) solution popular with managed service providers (MSPs). In its release notes, N-able described CVE-2026-86218 as a “critical-CVSS-rated vulnerability that could allow for pre-authenticated remote code execution on the N-central server.” N-able addressed the flaw on September 5 by releasing Hotfix 4 for N-central 2026. 3, bringing the build to version 2026. 3. 1. 14. “Customers running on-premises N-central … More → The post N-able patches critical N-central zero-day exploited in the wild (CVE-2026-86218) appeared first on Help Net Security .

·Help Net Security
Read →
Vulnerabilities & Patches
Emerging1 src

Back-to-back N-able bugs send admins on a patching spree

A max-severity zero-day bug could be affecting cybersecurity firm N-able’s N-central remote monitoring and management platform, the company said, even as administrators were applying a hotfix for two vulnerabilities disclosed just a day earlier. The latest flaw, tracked as CVE-2026-86218, is a remote code execution bug that can give an attacker access to an N-central server without authentication. Through its incident page, the company said the new vulnerability is unrelated to the two flaws disclosed on September 5, and has already found active exploitation. “Unlike the earlier vulnerabilities, this newly identified vulnerability has been observed being exploited in the wild,” it said, adding that it is investigating the matter and has taken steps to help protect customer environments. These steps include applying the mitigations to all hosted N-central instances.

·CSO Online
Read →
Vulnerabilities & Patches
Emerging1 src

Critical N-able N-central Flaw Enables Unauthenticated Pre-Auth Remote Code Execution

N-able has issued an urgent security update for a critical vulnerability in its N-central remote monitoring and management (RMM) platform that could let an unauthenticated attacker execute code on a vulnerable server before logging in. Tracked as CVE-2026-86218, the issue is fixed in N-central 2026. 3 Hotfix 4, build 2026. 3. 1. 14. N-central is used by managed service providers and IT teams to administer endpoints and customer environments from a central console. A pre-authentication remote code execution flaw is especially serious in that role: exploitation would not require valid N-central credentials, potentially giving an attacker a foothold on the management server that can span the administered infrastructure.

·CyberPress
Read →

You've reached the end of current stories for this search.