Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Merz to respond as Germany’s far-right AfD wins key state election – Europe live | Germany

    September 7, 2026

    N-able patches max severity N-central flaw amid ongoing attacks

    September 7, 2026

    Liquid Network Pauses After $320M Bitcoin Withdrawal

    September 7, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Merz to respond as Germany’s far-right AfD wins key state election – Europe live | Germany
    • N-able patches max severity N-central flaw amid ongoing attacks
    • Liquid Network Pauses After $320M Bitcoin Withdrawal
    • New Terrorist Technologies 25 Years After 9/11
    • Tiny cash buffers leave small UK TV firms at risk of going bust, analysis finds | Television industry
    • Europe cannot afford to lose the race for biomedical innovation – POLITICO
    • Chancellor John Healey to say UK economy ‘turning a corner’ despite debt concerns
    • ‘We can win here’: Zack Polanski presses the flesh in Holborn and St Pancras | Green party
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Monday, September 7
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    N-able patches max severity N-central flaw amid ongoing attacks

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 7, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    N-able has released an emergency hotfix for a maximum-severity remote code execution (RCE) flaw affecting its N-central remote monitoring and management (RMM) platform.

    IT departments and managed service providers (MSPs) use the N-central platform to monitor, manage, and maintain client networks and devices from a centralized web-based console.

    Tracked as CVE-2026-86218, this RCE vulnerability allows threat actors without privileges to execute malicious code on unpatched N-central instances exposed online in low-complexity attacks.

    N-able addressed the flaw on Saturday by releasing N-central 2026.3 Hotfix 4 and urging customers to patch as soon as possible.

    “At this time, we have no confirmations that this vulnerability has been exploited in production environments, but unpatched systems remain at risk,” the company said.

    “Customers running on-premises N-central deployments should upgrade to N-central 2026.3 HF4 immediately to protect their environment.”

    Internet security nonprofit Shadowserver Foundation now tracks nearly 1,500 N-central servers exposed online, most of them located in the United States and Europe.

    Internet-exposed N-able instances
    Internet-exposed N-able N-central instances (Shadowserver)

    Evidence of active exploitation​

    While N-able has yet to confirm that the CVE-2026-86218 flaw is being targeted, cybersecurity company Huntress has flagged it as a potential zero-day, along with two high-severity vulnerabilities (tracked as CVE-2026-86206 and CVE-2026-86207, and also patched over the weekend) that can allow attackers to bypass authentication and gain full access to the vulnerable N-central platform.

    “In our 9/5/26 update [..], we had said we could not rule out whether the two previous vulnerabilities released (CVE-2026-86206 and CVE-2026-86207) were the ones that were exploited in the instance seen in the patched production environment of one of our customers,” Huntress said.

    “Because logs on the compromised N-central server had already rotated, we are also unable to say whether this new CVE was the vulnerability exploited in that case.”

    “On-premises N-central users must apply HF4 immediately, as systems running HF3 remain vulnerable to this newly disclosed flaw,” Huntress warned.

    One year ago, N-able released security updates for two N-central vulnerabilities (CVE-2025-8875 and CVE-2025-8876) that attackers were exploiting in the wild.

    Days later, Shadowserver found that 880 N-central servers were still vulnerable to attacks exploiting the two security flaws even after CISA ordered federal agencies to patch their systems within a week and urged all security teams to also prioritize securing their systems against ongoing attacks.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report

    attacks Flaw Max Nable Ncentral ongoing Patches severity
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    ChatGPT Astra is now rolling out to $20 Plus subscription

    Iran warns of ‘faster, heavier, more painful response’ to US attacks

    Attackers conceal phishing lures using invisible Unicode characters

    Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication

    US military disabled ad tracking on troops’ devices following reports of targeted attacks

    Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Merz to respond as Germany’s far-right AfD wins key state election – Europe live | Germany

    September 7, 2026

    N-able patches max severity N-central flaw amid ongoing attacks

    September 7, 2026

    Liquid Network Pauses After $320M Bitcoin Withdrawal

    September 7, 2026

    New Terrorist Technologies 25 Years After 9/11

    September 7, 2026
    Latest Posts

    Quantum computing nears commercial breakthrough, IBM CEO says

    August 1, 2026

    Amgen says cloud data breach exposed patient health, proprietary info

    August 1, 2026

    Snapchat joins other platforms in the fight against ‘AI slop’

    August 1, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Merz to respond as Germany’s far-right AfD wins key state election – Europe live | Germany

    September 7, 2026

    N-able patches max severity N-central flaw amid ongoing attacks

    September 7, 2026

    Liquid Network Pauses After $320M Bitcoin Withdrawal

    September 7, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.