daily cyber × ai intelligence

index

tagged

[CVE-2026-86218]

2 editions · 2 items

September 10, 2026

  • N-able N-central moved from disputed to confirmed: CISA added CVE-2026-86218 (CVSS 10.0 static code injection, pre-auth RCE) to KEV with an FCEB deadline of 11 September, and N-able told customers it "has been observed being exploited in the wild." watchTowr reproduced it; Huntress still cannot say which bug hit its customer's fully patched appliance on 4 September because of limited on-box logging, and cannot rule out the CVE-2026-86206/86207 admin-creation chain (The Hacker News; earlier coverage). · Exploited in the Wild

in One Exploit Kit, Four Espionage Crews: BlueMoon Turns Chrome's Patch Gap Into a Shared Weapon

September 8, 2026

  • N-able N-central shipped Hotfix 4 (build 2026.3.1.14) in the early hours of 6 September UTC for CVE-2026-86218, a static code injection flaw (CWE-96) rated CVSS 4.0 10.0 by N-able as CNA, allowing unauthenticated RCE on the N-central server. Every on-prem build below 2026.3.1.14 is affected, including servers patched to Hotfix 3 roughly eight hours earlier; hosted NCOD instances are already patched. The release notes say a third party disclosed it and that N-able has "no confirmations" of production exploitation, while the incident notice on the status page says the flaw "has been observed being exploited in the wild" (The Hacker News, BleepingComputer). No IoCs, no interim mitigation, no detection guidance beyond auditing N-central user accounts. Huntress, tracking N-central attacks since August, says it reproduced a PoC exploit chain against build 2026.3.1.10 but the appliance logs had rotated, leaving it unable to say which CVE was used; it advises IP allowlisting or VPN-only access to the console (earlier coverage). · Vulnerabilities & Exploits

in N-able Ships a Fourth N-central Hotfix in Five Weeks — and Can't Agree Whether It's Exploited