Find notable cyber news and cases, enriched with sources, timelines, and signals.

N-central pre-auth RCE flaw (CVE-2026-86218)

Vulnerability
First reported
Last updated
Happening score
H score 56
1 unique sources, 1 articles

Summary

Hide ▲

CVE-2026-86218 in N-central now has Hotfix 4, and the flaw can let unauthenticated attackers execute code on affected servers. Every on-premises build below 2026.3.1.14 is affected, including systems that had already installed Hotfix 3. N-able's notices conflict on exploitation, with one saying there are no confirmed production cases and another saying the flaw has been observed being exploited in the wild.

Related Happenings

StormEncryptor ransomware deployment by Storm-1175

Malware Activity
H score40 First: 10.08.2026 20:42 Last: 10.08.2026 20:42 Sources 1

About this happening: Storm-1175 is deploying StormEncryptor, a previously undocumented ransomware strain that appends .encrypted to encrypted files and drops !!!README_FIRST!!!.txt ran...

N-central authentication bypass authentication bypass flaw (multiple vulnerabilities)

Vulnerability
H score49 First: 03.08.2026 09:41 Last: 03.08.2026 09:41 Sources 1

About this happening: CVE-2026-18577 is an authentication-bypass vulnerability in N-able N-central that affects hosted and on-premises servers and was used in active exploitation be...

Latest development: 04.08.2026 10:00

CISA added CVE-2026-18577 in N-able N-central to its Known Exploited Vulnerabilities catalog after reports of active exploitation in the wild. The flaw is an incomplete patch for CVE-2026-18556 that can allow authentication bypass and account takeover in susceptible versions, and N-able said the issue is addressed in version 2026.3 HF1. Federal Civilian Executive Branch agencies were told to apply the fixes by August 6, 2026 and review N-central Take Control activity.

Warlock ransomware post-exploitation tooling upgrades

Malware Activity
H score38 First: 17.03.2026 17:36 Last: 17.03.2026 17:36 Sources 1

About this happening: The Warlock ransomware group has upgraded its post-exploitation toolset with BYOVD, TightVNC, and Yuze, making intrusions harder to detect and interrupt. In an obs...

Timeline

  1. 07.09.2026 11:31 2 articles · 2h ago

    N-central pre-auth RCE flaw (CVE-2026-86218)

    Initial Disclosure

    Hotfix 4 closed CVE-2026-86218 in N-central, a pre-authentication RCE flaw affecting every on-premises build before 2026.3.1.14. The patch applied even to systems that had already installed Hotfix 3.

    Show sources