Skip to main content
CSO Online·US·

Back-to-back N-able bugs send admins on a patching spree

A max-severity zero-day bug could be affecting cybersecurity firm N-able’s N-central remote monitoring and management platform, the company said, even as administrators were applying a hotfix for two vulnerabilities disclosed just a day earlier. The latest flaw, tracked as CVE-2026-86218 , is a remote code execution bug that can give an attacker access to an N-central server without authentication. Through its incident page , the company said the new vulnerability is unrelated to the two flaws disclosed on September 5, and has already found active exploitation. “Unlike the earlier vulnerabilities, this newly identified vulnerability has been observed being exploited in the wild,” it said, adding that it is investigating the matter and has taken steps to help protect customer environments. These steps include applying the mitigations to all hosted N-central instances. On-premises customers, however, remain exposed until they download and upgrade their N-central deployments using instructions provided on the N-able support portal. In a blog post , Huntress disclosed an undocumented exploit chain involving CVE-2026-86206 and CVE-2026-86207 , the two flaws N-able had disclosed on Septe

Read releases like this the second they cross the wire.

1,200+ feeds from 80+ newswires in one live cockpit — saved searches, instant alerts, AI summaries. 7-day free trial, no card required.

Start the free trial →

Your announcement next? Distribute your press release to the global wires with PPN Source — and track its pickup live on PPN World.

PPN Source →
Shared via PPN World — real-time press release intelligence.