Gli aggiornamenti di sicurezza rilasciati da N-able sanano tre vulnerabilità, di cui una con gravità "critica" ed una con gravità "alta", in N-central, piattaforma per il monitoraggio e la gestione remota delle infrastrutture IT. Tra queste si segnala la CVE-2026-86218 che risulta essere attivamente sfruttata in rete.
Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv4.0: 10.0, CVEs: CVE-2026-86206, CVE-2026-86207, CVE-2026-86218, Summary: Hotfix 4 includes security fixes for CVE-2026-86218 which is a critical-CVSS-rated vulnerability that could allow for pre-authenticated remote code execution on the N-central server. Hotfix 3 includes security fixes for CVE-2026-86206 and CVE-2026-86207 which are high-CVSS-rated vulnerabilities that could allow an unauthorized party to…
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-75650 Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability CVE-2026-81963 Microsoft Windows Link Following Vulnerability CVE-2026-85880 Microsoft Windows Heap-Based Buffer Overflow Vulnerability CVE-2026-86218 N-able N-central Static Code Injection Vulnerability These types of vulnerabilities…
OverviewWhile conducting research into a recent N-able N-central authentication bypass vulnerability (CVE-2026-18577), Rapid7 Labs discovered two new vulnerabilities affecting the latest version of N-central. When chained together, these two vulnerabilities allow a remote unauthenticated attacker to bypass authentication and create a new attacker-controlled System administrator account on an affected server.CVE IDDescriptionCWECVSSv4CVE-2026-86206Semicolon/Forwarded access-control bypassCWE…
N-able heeft een kwetsbaarheid verholpen in N-central versies eerder dan 2026.3.1.14. De kwetsbaarheid betreft een pre-authenticatie remote code execution flaw. Een aanvaller kan hierdoor op afstand willekeurige code uitvoeren op het getroffen systeem zonder enige vorm van authenticatie. Alle installaties die draaien op de kwetsbare versies van N-central zijn getroffen. Klanten met een on-premises N-central-omgeving wordt geadviseerd zo snel mogelijk te upgraden naar N-central 2026.3 HF4. Voor…
N-able has released an emergency hotfix for a maximum-severity remote code execution (RCE) flaw affecting its N-central remote monitoring and management (RMM) platform. [...]