← nejvýznamnější zprávy · všechny zprávy

SPOJENO AI KEV ✓ (2 z 4) EPSS 0.54 (nejvyšší)

N-able patches max severity N-central flaw amid ongoing attacks

N-able has released an emergency hotfix for a maximum-severity remote code execution (RCE) flaw affecting its N-central remote monitoring and management (RMM) platform. [...]

Číst originál na BleepingComputer →

7 zpráv z 7 zdrojů · první 7. 9. 08:17 · poslední 9. 9. 12:53 CZ · EN/orig

N-able IT FI CA US NL

tg: zneužíváno tg: zranitelnost tg: rozbor tg: novinka v produktu tp: identita

CVE v události 4

CVEhodnoceníKEVEPSS
CVE-2026-18577 8.2 4.0 · N-able KEV ✓ 0.54
CVE-2026-86206 6.9 4.0 · N-able 0.01
CVE-2026-86207 7.7 4.0 · N-able 0.01
CVE-2026-86218 10.0 4.0 · N-able KEV ✓ 0.07

Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE. Advisory v textu uvádí CVSS 10.0.

Tahle CVE jsem vytáhl z širšího textu článku: CVE-2025-8875, CVE-2025-8876. Neukazuju u nich proto fakta z katalogů výše, a to preventivně, protože článek se na ně mohl jen odkazovat, třeba jako na starší kauzu.

Jak se o tom psalo 7

  1. · CSIRT Itálie (ACN) IT

    N-able: rilevato sfruttamento in rete della CVE-2026-86218 in N-central

    Gli aggiornamenti di sicurezza rilasciati da N-able sanano tre vulnerabilità, di cui una con gravità "critica" ed una con gravità "alta", in N-central, piattaforma per il monitoraggio e la gestione remota delle infrastrutture IT. Tra queste si segnala la CVE-2026-86218 che risulta essere attivamente sfruttata in rete.

  2. · NCSC-FI FI

    N-central 2026.3 Hotfix 4 – CVE-2026-86218 & Hotfix 3 - CVE-2026-86206 and CVE-2026-86207

    Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv4.0: 10.0, CVEs: CVE-2026-86206, CVE-2026-86207, CVE-2026-86218, Summary: Hotfix 4 includes security fixes for CVE-2026-86218 which is a critical-CVSS-rated vulnerability that could allow for pre-authenticated remote code execution on the N-central server. Hotfix 3 includes security fixes for CVE-2026-86206 and CVE-2026-86207 which are high-CVSS-rated vulnerabilities that could allow an unauthorized party to…

  3. · Cyber Centre Kanada CA

    N-able security advisory (AV26-885)

    Serial Number: AV26-885Date: September 8, 2026 As of September 6, 2026, N-able is affected by vulnerabilities in the following product: N-central Prior to 2026.3.1.14 N-able indicates that CVE-2026-86218 is being exploited in the wild. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. N-central 2026.3 Hotfix 4 – CVE-2026-86218 2026.3 HF4 Release Notes Release Notes | N-able Status | N-able Status Page

  4. · Rapid7 US

    CVE-2026-86206, CVE-2026-86207: N-able N-central Authentication Bypass (FIXED)

    OverviewWhile conducting research into a recent N-able N-central authentication bypass vulnerability (CVE-2026-18577), Rapid7 Labs discovered two new vulnerabilities affecting the latest version of N-central. When chained together, these two vulnerabilities allow a remote unauthenticated attacker to bypass authentication and create a new attacker-controlled System administrator account on an affected server.CVE IDDescriptionCWECVSSv4CVE-2026-86206Semicolon/Forwarded access-control bypassCWE…

  5. · CISA KEV US

    N-able N-central Static Code Injection Vulnerability (CVE-2026-86218)

    CISA added CVE-2026-86218 to the Known Exploited Vulnerabilities catalog. Affected product: N-able N-central. Remediation due date: 2026-09-11.

  6. · NCSC-NL NL

    NCSC-2026-0342 [1.00] [H/H] Kwetsbaarheid verholpen in N-central van N-able

    N-able heeft een kwetsbaarheid verholpen in N-central versies eerder dan 2026.3.1.14. De kwetsbaarheid betreft een pre-authenticatie remote code execution flaw. Een aanvaller kan hierdoor op afstand willekeurige code uitvoeren op het getroffen systeem zonder enige vorm van authenticatie. Alle installaties die draaien op de kwetsbare versies van N-central zijn getroffen. Klanten met een on-premises N-central-omgeving wordt geadviseerd zo snel mogelijk te upgraden naar N-central 2026.3 HF4. Voor…

  7. · BleepingComputer US nadpis události

    N-able patches max severity N-central flaw amid ongoing attacks

    N-able has released an emergency hotfix for a maximum-severity remote code execution (RCE) flaw affecting its N-central remote monitoring and management (RMM) platform. [...]