Výsledky hledání

výrobce: N-able× v celém archivu zrušit filtry

11 karet z 15 položek CZ · EN/orig

2

SPOJENO PŘES CVE N-able: rilevato sfruttamento in rete della CVE-2026-86218 in N-central

Gli aggiornamenti di sicurezza rilasciati da N-able sanano tre vulnerabilità, di cui una con gravità "critica" ed una con gravità "alta", in N-central, piattaforma per il monitoraggio e la gestione remota delle infrastrutture IT. Tra queste si segnala la CVE-2026-86218 che risulta essere attivamente sfruttata in rete.

KEV ✓ EPSS 0.01 CVE-2026-86218 N-able IT CA US

tg: zneužíváno tg: zranitelnost

· CSIRT Itálie (ACN) · N-able: rilevato sfruttamento in rete della CVE-2026-86218 in N-central · Cyber Centre Kanada · N-able security advisory (AV26-885) · CISA KEV · N-able N-central Static Code Injection Vulnerability (CVE-2026-86218)

N-central 2026.3 Hotfix 4 – CVE-2026-86218 & Hotfix 3 - CVE-2026-86206 and CVE-2026-86207

Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv4.0: 10.0, CVEs: CVE-2026-86206, CVE-2026-86207, CVE-2026-86218, Summary: Hotfix 4 includes security fixes for CVE-2026-86218 which is a critical-CVSS-rated vulnerability that could allow for pre-authenticated remote code execution on the N-central server. Hotfix 3 includes security fixes for CVE-2026-86206 and CVE-2026-86207 which are high-CVSS-rated vulnerabilities that could allow an unauthorized party to…

KEV ✓ EPSS 0.01 CVSS 10.0 CVE-2026-86206 CVE-2026-86207 CVE-2026-86218 N-able FI

tg: zranitelnost tg: novinka v produktu

· NCSC-FI · N-central 2026.3 Hotfix 4 – CVE-2026-86218 & Hotfix 3 - CVE-2026-86206 and CVE-2026-86207

2

CISA Adds Four Known Exploited Vulnerabilities to Catalog

CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-75650 Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability CVE-2026-81963 Microsoft Windows Link Following Vulnerability CVE-2026-85880 Microsoft Windows Heap-Based Buffer Overflow Vulnerability CVE-2026-86218 N-able N-central Static Code Injection Vulnerability These types of vulnerabilities…

KEV ✓ EPSS 0.02 CVE-2026-75650 CVE-2026-81963 CVE-2026-85880 CVE-2026-86218 Adobe Magento Microsoft N-able veřejná správa US

tg: zneužíváno tg: zranitelnost tg: regulace

· CISA Advisories · CISA Adds Four Known Exploited Vulnerabilities to Catalog

CVE-2026-86206, CVE-2026-86207: N-able N-central Authentication Bypass (FIXED)

OverviewWhile conducting research into a recent N-able N-central authentication bypass vulnerability (CVE-2026-18577), Rapid7 Labs discovered two new vulnerabilities affecting the latest version of N-central. When chained together, these two vulnerabilities allow a remote unauthenticated attacker to bypass authentication and create a new attacker-controlled System administrator account on an affected server.CVE IDDescriptionCWECVSSv4CVE-2026-86206Semicolon/Forwarded access-control bypassCWE…

KEV ✓ EPSS 0.54 CVE-2026-18577 CVE-2026-86206 CVE-2026-86207 N-able US

tg: zranitelnost tg: rozbor tp: identita

· Rapid7 · CVE-2026-86206, CVE-2026-86207: N-able N-central Authentication Bypass (FIXED)

2

NCSC-2026-0342 [1.00] [H/H] Kwetsbaarheid verholpen in N-central van N-able

N-able heeft een kwetsbaarheid verholpen in N-central versies eerder dan 2026.3.1.14. De kwetsbaarheid betreft een pre-authenticatie remote code execution flaw. Een aanvaller kan hierdoor op afstand willekeurige code uitvoeren op het getroffen systeem zonder enige vorm van authenticatie. Alle installaties die draaien op de kwetsbare versies van N-central zijn getroffen. Klanten met een on-premises N-central-omgeving wordt geadviseerd zo snel mogelijk te upgraden naar N-central 2026.3 HF4. Voor…

N-able NL

tg: zneužíváno tg: zranitelnost

· NCSC-NL · NCSC-2026-0342 [1.00] [H/H] Kwetsbaarheid verholpen in N-central van N-able

1

SPOJENO PŘES CVE N-able security advisory (AV26-769) - Update 2

Serial Number: AV26-769Date: August 4, 2026Updated: August 7, 2026 As of August 2, 2026, N-able is affected by vulnerabilities in the following product: N-central Prior to 2026.3.1.10 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. On August 3, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-18577 to their Known Exploited Vulnerabilities (KEV) Database. Update 1 On August…

KEV ✓ EPSS 0.54 CVE-2026-18556 CVE-2026-18577 N-able CA US

· Cyber Centre Kanada · N-able security advisory (AV26-769) - Update 2 · Rapid7 · CVE-2026-18577: N-able N-central Authentication Bypass Exploited in the Wild

3

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-9198 IBM Langflow Code Injection Vulnerability CVE-2026-18556 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability CVE-2026-34486 Apache Tomcat Missing Encryption of Sensitive Data Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the…

KEV ✓ EPSS 0.99 CVE-2026-18556 CVE-2026-34486 CVE-2026-9198 IBM N-able Apache veřejná správa US

· CISA Advisories · CISA Adds Three Known Exploited Vulnerabilities to Catalog

SPOJENO PŘES CVE N-able N-central exploitation results in RMM tool deployment

After compromising systems via CVE-2026-18577, threat actors use the additional RMM tools and network tunnels to establish persistent remote accessCategories: Threat ResearchTags: RMM, N-able, vulnerability

KEV ✓ EPSS 0.54 CVE-2026-18577 N-able GB US

· Sophos Threat Research · N-able N-central exploitation results in RMM tool deployment · CISA KEV · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability (CVE-2026-18577)

1