Search/N-able: rilevato sfruttamento in rete della CVE-2026-86218 in N-central
Story

N-able: rilevato sfruttamento in rete della CVE-2026-86218 in N-central

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 11, 2026. The vulnerability in question is CVE-2026-86218 (CVSS score: 10.0), which has been described as a case of static code injection. It has been patched in N-central 2026.3 Hotfix 4, released on September 5, 2026. "N-able N-central contains a static code injection vulnerability that could allow for pre-authentication remote code execution," CISA said. The development came shortly after Huntress said it commenced an investigation following the compromise of a customer's fully patched N-central…

CVEs
1
Highest CVSS
9.8
In KEV
1
Sources
4
Connections
5 relationships
N-able: rilevato sfruttamento in rete della CVE-2026-86218 in N-central
N-able: rilevato sfruttamento in rete della CVE-2026-86218 in N-central Alert AL04/260909/CSIRT-ITA Sintesi Gli aggiornamenti di sicurezza rilasciati da N-able sanano tre vulnerabilità, di cui una con gravità "critica" ed una con gravità "alta", in N-central, piattaforma per il monitoraggio e la gestione remota delle infrastrutture IT. Tra queste si segnala la CVE-2026-86218 che risulta essere attivamente sfruttata in rete. Tali vulnerabilità, qualora sfruttate, potrebbero consentire ad un attaccante remoto di eludere i meccanismi di autenticazione ed eseguire codice arbitrario sui sistemi interessati. Tipologia Remote Code Execution Authentication Bypass Descrizione e potenziali impatti Nel dettaglio, la vulnerabilità identificata tramite la CVE-2026-86218 - di tipo "Remote Code Execution" e con score CVSS v4.0 pari a 10 - è dovuta alla non adeguata applicazione, nel server N-central, delle misure di sanitizzazione delle direttive basate su codice fornite da un utente esterno. Un attaccante remoto, attraverso l'invio di richieste HTTP/HTTPS appositamente predisposte a una porta esposta del server N-central, potrebbe iniettare direttive arbitrarie in file statici salvati dal sistema. Quando tali file vengono successivamente elaborati dal server, le direttive iniettate vengono eseguite, consentendo l'esecuzione di codice arbitrario nel sistema interessato. Prodotti e/o versioni affette N-able N-central, versioni precedenti alla 2026.3.1.14 Azioni di mitigazione Ove non provveduto, si raccomanda di aggiornare i prodotti vulnerabili e applicare le mitigazioni fornite dal vendor, seguendo le indicazioni del bollettino di sicurezza riportato nella sezione Riferimenti. Di seguito sono riportate le sole CVE relative alle vulnerabilità con gravità “critica” ed "alta":
acn.gov.itSep 9, 2026extracted
N-able N-central Pre-Auth RCE Flaw Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 11, 2026. The vulnerability in question is CVE-2026-86218 (CVSS score: 10.0), which has been described as a case of static code injection. It has been patched in N-central 2026.3 Hotfix 4, released on September 5, 2026. "N-able N-central contains a static code injection vulnerability that could allow for pre-authentication remote code execution," CISA said. The development came shortly after Huntress said it commenced an investigation following the compromise of a customer's fully patched N-central production environment on September 4, 2026. However, it remains unclear if the intrusion involved CVE-2026-86218 or two other vulnerabilities (CVE-2026-86206 and CVE-2026-86207) that were patched by N-able the same day with N-central 2026.3 Hotfix 3. CVE-2026-86206 and CVE-2026-86207 can be chained together to allow a remote unauthenticated attacker to bypass authentication and create a new attacker-controlled System Administrator account on an affected server, per Rapid7's Stephen Fewer, who discovered and reported them. "Due to limited historical logging available directly on the appliance, we cannot definitively confirm which specific exploit the threat actor used to achieve their compromise, nor can we rule out the use of alternative vulnerabilities," Huntress noted. In a separate "urgent" notice sent directly to customers, N-able said CVE-2026-86218 "has been observed being exploited in the wild" and that it's "actively investigating this matter and have taken additional steps to help protect customer environments." It also urged customers to apply the hotfix immediately. Preemptive exposure management firm watchTowr said it has successfully reproduced CVE-2026-86218, adding that the pre-authentication vulnerability enables remote code execution and allows attackers to make changes in N-central that can propagate across all connected systems. "This is precisely why N-central is so strategically valuable to threat actors, especially ransomware gangs," Yordan Ganchev, principal threat intelligence specialist at watchTowr, said. "The product is widely used by MSPs, MSSPs, and large IT organizations to manage entire customer and corporate environments. Compromise N-central, and you gain access to all connected computers and downstream systems. Based on historical events, AI-enabled attackers are unlikely to be far behind." "Organizations running internet-facing N-central instances should prioritize upgrading to a patched release. However, as is now quickly becoming the new normal, patching alone is not enough. Organizations must also review their environment for indicators of compromise and anomalous activity that suggest the vulnerability has already been exploited before patching. Ransomware threat actors have historically exploited this product in past campaigns, and this vulnerability is as severe as it gets."
thehackernews.comSep 9, 2026extracted
N-able Releases Hotfix for Critical Remote Code Execution Vulnerability
Managed IT software provider N-able has released a new hotfix that includes a patch for a critical remote code execution (RCE) vulnerability. CVE-2026-86218 is a critical pre-authentication RCE flaw in N-central, N-able’s remote monitoring and management platform. It was disclosed by the software provider on September 6 and was allocated a maximum-severity rating (CVSS) of 10. The vulnerability affects N-central versions before 2026.3.1.14 and can allow an unauthenticated attacker to execute code on the N-central server. N-able has not publicly disclosed the affected component or exploitation method. It said it has found no evidence that CVE-2026-86218 has been exploited in production environments. Meanwhile, the software provider released a patch for the vulnerability in its N-central 2026.3 Hotfix 4, which brings the build to 2026.3.1.14. This is the latest of five vulnerabilities affecting N-able products in a few weeks. CVE-2026-18556 and CVE-2026-18577 are high-severity authentication bypasses that were found to be exploited earlier in 2026 – and added to the US Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities (KEV) catalog in August. Patches for those two vulnerabilities were included in N-able’s HF1 and HF2 hotfixes, published on August 2 and 6. CVE-2026-86207 is a high-severity authentication bypass affecting internal only APIs and CVE-2026-86206 is a high-severity access-control filter bypass exposing internal APIs. They were both patched in N-able’s HF3 hotfix on September 5. Image credits: Cristi Dangeorge / Shutterstock.com
infosecurity-magazine.comSep 7, 2026extracted
N-able patches critical N-central zero-day exploited in the wild (CVE-2026-86218)
N-able patches critical N-central zero-day exploited in the wild (CVE-2026-86218) N-able released an emergency hotfix for CVE-2026-86218, a remote code execution (RCE) flaw affecting N-central, its remote monitoring and management (RMM) solution popular with managed service providers (MSPs). In its release notes, N-able described CVE-2026-86218 as a “critical-CVSS-rated vulnerability that could allow for pre-authenticated remote code execution on the N-central server.” N-able addressed the flaw on September 5 by releasing Hotfix 4 for N-central 2026.3, bringing the build to version 2026.3.1.14. “Customers running on-premises N-central deployments should upgrade to N-central 2026.3 HF4 immediately to protect their environment,” the company added. “This vulnerability was responsibly disclosed by a third party through our security disclosure program. At this time, we have no confirmations that this vulnerability has been exploited in production environments, but unpatched systems remain at risk,” the company noted. In a separate notice sent directly to customers, marked as urgent and calling for the hotfix to be applied immediately, N-able said CVE-2026-86218 “has been observed being exploited in the wild” and called it a zero-day, contradicting the claims in its public advisory. The notice listed both hosted and on-premises N-central deployments as impacted, spanning the Americas, APAC, and Europe. Cybersecurity firm Huntress also flagged CVE-2026-86218 as a potential zero-day, alongside two high-severity vulnerabilities, CVE-2026-86206 and CVE-2026-86207, which N-able patched over the weekend and which can allow attackers to bypass authentication and gain unrestricted access to the N-central platform. The firm says it learned of the flaw through a Discord post from an N-able employee in the MSPGeek community, ahead of N-able’s own public hotfix announcement. “In our 9/5/26 update, we had said we could not rule out whether the two previous vulnerabilities released (CVE-2026-86206 and CVE-2026-86207) were the ones that were exploited in the instance seen in the patched production environment of one of our customers. Because logs on the compromised N-central server had already rotated, we are also unable to say whether this new CVE was the vulnerability exploited in that case,” Huntress explained. “As a precaution, we recommend auditing your N-central user accounts to ensure that there are no unexpected users,” N-able concluded.
helpnetsecurity.comSep 7, 2026extracted