September 10, 2026
- N-able N-central moved from disputed to confirmed: CISA added CVE-2026-86218 (CVSS 10.0 static code injection, pre-auth RCE) to KEV with an FCEB deadline of 11 September, and N-able told customers it "has been observed being exploited in the wild." watchTowr reproduced it; Huntress still cannot say which bug hit its customer's fully patched appliance on 4 September because of limited on-box logging, and cannot rule out the CVE-2026-86206/86207 admin-creation chain (The Hacker News; earlier coverage). · Exploited in the Wild
in One Exploit Kit, Four Espionage Crews: BlueMoon Turns Chrome's Patch Gap Into a Shared Weapon