September 10, 2026
- N-able N-central moved from disputed to confirmed: CISA added CVE-2026-86218 (CVSS 10.0 static code injection, pre-auth RCE) to KEV with an FCEB deadline of 11 September, and N-able told customers it "has been observed being exploited in the wild." watchTowr reproduced it; Huntress still cannot say which bug hit its customer's fully patched appliance on 4 September because of limited on-box logging, and cannot rule out the CVE-2026-86206/86207 admin-creation chain (The Hacker News; earlier coverage).
· Exploited in the Wild
in One Exploit Kit, Four Espionage Crews: BlueMoon Turns Chrome's Patch Gap Into a Shared Weapon
September 8, 2026
- N-able N-central shipped Hotfix 4 (build 2026.3.1.14) in the early hours of 6 September UTC for CVE-2026-86218, a static code injection flaw (CWE-96) rated CVSS 4.0 10.0 by N-able as CNA, allowing unauthenticated RCE on the N-central server. Every on-prem build below 2026.3.1.14 is affected, including servers patched to Hotfix 3 roughly eight hours earlier; hosted NCOD instances are already patched. The release notes say a third party disclosed it and that N-able has "no confirmations" of production exploitation, while the incident notice on the status page says the flaw "has been observed being exploited in the wild" (The Hacker News, BleepingComputer). No IoCs, no interim mitigation, no detection guidance beyond auditing N-central user accounts. Huntress, tracking N-central attacks since August, says it reproduced a PoC exploit chain against build 2026.3.1.10 but the appliance logs had rotated, leaving it unable to say which CVE was used; it advises IP allowlisting or VPN-only access to the console (earlier coverage).
· Vulnerabilities & Exploits
in N-able Ships a Fourth N-central Hotfix in Five Weeks — and Can't Agree Whether It's Exploited
September 6, 2026
- A new N-able N-central chain can create unauthorized administrator accounts. Huntress built a PoC combining CVE-2026-86206 and CVE-2026-86207, which it says is distinct from the August flaws. Huntress says a hotfix is available; its follow-up recommends hunting for anomalous accounts using
.invalid email addresses.
· Vulnerabilities & Exploits
in One Loophole, 100 Agents, 27 Minutes
August 21, 2026
- N-able Passportal exposed password vault master keys. The MSP-favoured credential manager remains structurally risky post-patch because of its cloud-based key handling (Dark Reading), with the technical breakdown at amibeingpwned.
· Cloud & Identity
in Microsoft's Own Defender Driver Becomes the EDR Killer
August 8, 2026
- N-able N-central attackers have now reached customer networks, and a second emergency hotfix has shipped. Build 2026.3.1.10 (Thursday) supersedes Monday's 2026.3.1.7; N-able confirms full account takeover is possible and urges immediate on-prem patching (earlier coverage). Kevin Beaumont warns a ransomware group already has the exploit, saying he spent hours helping a government office hit with ransomware via this bug. The Register, @GossiTheDog
· Vulnerabilities & Exploits
in OpenAI Pauses Its Astra Model After It Hits the "Critical" Cyber Threshold
August 7, 2026
- N-able N-central attackers are persisting via Cloudflare Tunnels even after patching, per Gossi — check N-central servers for Cloudflare Tunnel traffic. CISA also added the auth-bypass (CVE-2026-18577) to KEV alongside Langflow and Tomcat (earlier coverage). Kevin Beaumont
· Vulnerabilities & Exploits
in Meta Becomes the Fourth Lab to Admit Its AI Hacked a Stranger
August 4, 2026
- N-able N-central auth bypass (CVE-2026-18577) is under active exploitation, and the first fix didn't hold. Over the weekend N-able discovered a second authentication-bypass vector that grants attackers administrator access to both hosted and on-prem N-central servers, letting them reach the customer systems those servers manage; build 2026.3.1.7 (shipped Aug 2) is the first unaffected version (The Hacker News, BleepingComputer). Huntress has published exploitation details and detection guidance (Huntress). Continues our earlier coverage.
· Vulnerabilities & Exploits
- The Iran-linked water-sector campaign has spread to Georgia and Michigan. Officials now count OT compromises at water and wastewater utilities across at least seven US states, prompting expanded protective measures (The Register, SecurityWeek). Continues earlier coverage.
· Threat Activity
in Attackers Seize N-central RMM Servers After N-able's Second Fix Falls Short
August 3, 2026
- N-able N-central has a critical vulnerability that grants attackers "god-mode" access to the RMM console, according to Huntress, which is actively tracking it. An attacker who exploits it could run scripts, push tooling, and open remote sessions on any managed endpoint — the classic RMM-to-fleet blast radius that makes these platforms prime initial-access targets.
· Vulnerabilities & Exploits
in God-Mode Access in N-able N-central Tops a Day of Fresh Exploits