N-able security patch release for CVE-2026-86218
Security Patch Release
Summary
Hide ▲
Show ▼
N-able released N-central 2026.3 HF4 to close CVE-2026-86218, a maximum-severity RCE in the N-central RMM platform. The patch protects on-premises deployments exposed online, where unprivileged attackers could run code with low-complexity attacks. N-able urged customers to upgrade immediately, and systems still on HF3 remain at risk until they move to HF4.
Related Happenings
Adobe security patch release for CVE-2026-48362
Security Patch Release
H score43
First: 11.08.2026 19:50
Last: 11.08.2026 19:50
Sources 1
About this happening:
Adobe shipped a priority 1 update for ColdFusion that fixes 15 security defects, including flaws that could enable arbitrary code execution and application D...
Adobe security patch release for CVE-2026-48362
Security Patch ReleaseAbout this happening: Adobe shipped a priority 1 update for ColdFusion that fixes 15 security defects, including flaws that could enable arbitrary code execution and application D...
StormEncryptor ransomware deployment by Storm-1175
Malware Activity
H score40
First: 10.08.2026 20:42
Last: 10.08.2026 20:42
Sources 1
About this happening:
Storm-1175 is deploying StormEncryptor, a previously undocumented ransomware strain that appends .encrypted to encrypted files and drops !!!README_FIRST!!!.txt ran...
StormEncryptor ransomware deployment by Storm-1175
Malware ActivityAbout this happening: Storm-1175 is deploying StormEncryptor, a previously undocumented ransomware strain that appends .encrypted to encrypted files and drops !!!README_FIRST!!!.txt ran...
N-able security patch release for CVE-2026-18577
Security Patch Release
H score46
First: 03.08.2026 09:41
Last: 03.08.2026 09:41
Sources 1
About this happening:
N-able is warning that CVE-2026-18577 is being actively exploited against N-central on both hosted and on-premises servers. The vendor released hotfix 2026.3...
N-able security patch release for CVE-2026-18577
Security Patch ReleaseAbout this happening: N-able is warning that CVE-2026-18577 is being actively exploited against N-central on both hosted and on-premises servers. The vendor released hotfix 2026.3...
N-able N-central servers hit by network compromise
Incident
H score41
First: 03.08.2026 09:41
Last: 03.08.2026 09:41
Sources 1
About this happening:
N-able N-central is part of an ongoing authentication-bypass compromise that let attackers gain remote administrative access and reach managed systems through Take C...
N-able N-central servers hit by network compromise
IncidentAbout this happening: N-able N-central is part of an ongoing authentication-bypass compromise that let attackers gain remote administrative access and reach managed systems through Take C...
Latest development: 04.08.2026 10:00
CISA added CVE-2026-18577 in N-able N-central to the KEV catalog after reports of active exploitation, and N-able said a limited number of customers were compromised through the flaw. Successful exploitation can give attackers administrative access to vulnerable N-central servers and let them pivot through Take Control into managed endpoints.
SonicWall security patch release for CVE-2026-15409
Security Patch Release
H score54
First: 15.07.2026 00:23
Last: 15.07.2026 00:23
Sources 1
About this happening:
SonicWall released hotfix security updates for SMA1000 appliances after confirming active exploitation of CVE-2026-15409 and CVE-2026-15410. The fixes are availabl...
SonicWall security patch release for CVE-2026-15409
Security Patch ReleaseAbout this happening: SonicWall released hotfix security updates for SMA1000 appliances after confirming active exploitation of CVE-2026-15409 and CVE-2026-15410. The fixes are availabl...
Timeline
-
07.09.2026 09:17 2 articles · 2h ago
N-able releases N-central 2026.3 HF4 for CVE-2026-86218
Mitigation Patch UpdateN-able released N-central 2026.3 Hotfix 4 to fix CVE-2026-86218, a maximum-severity remote code execution flaw in the N-central remote monitoring and management platform that could let unprivileged attackers run malicious code on unpatched internet-exposed instances. The company urged on-premises customers to upgrade immediately and said it had no confirmation of production exploitation.
Show sources
- N-able patches max severity N-central flaw amid ongoing attacks — www.bleepingcomputer.com — 07.09.2026 09:17
- N-able patches max severity N-central flaw amid ongoing attacks — www.bleepingcomputer.com — 07.09.2026 09:17
-
07.09.2026 09:17 1 articles · 2h ago
Huntress flags CVE-2026-86218 as a potential zero-day in N-central
Technical Analysis UpdateHuntress flagged CVE-2026-86218 as a potential zero-day alongside CVE-2026-86206 and CVE-2026-86207, and warned that on-premises N-central systems running HF3 remain vulnerable until they move to HF4. Shadowserver Foundation said it was tracking nearly 1,500 N-central servers exposed online, most of them in the United States and Europe.
Show sources
- N-able patches max severity N-central flaw amid ongoing attacks — www.bleepingcomputer.com — 07.09.2026 09:17