
Back-to-back N-able bugs send admins on a patching spree
A max-severity zero-day bug could be affecting cybersecurity firm N-able’s N-central remote monitoring and management platform, the company said, even as administrators were applying a hotfix for two vulnerabilities disclosed just a day earlier.
The latest flaw, tracked as CVE-2026-86218, is a remote code execution bug that can give an attacker access to an N-central server without authentication.
Through its incident page, the company said the new vulnerability is unrelated to the two flaws disclosed on September 5, and has already found active exploitation. “Unlike the earlier vulnerabilities, this newly identified vulnerability has been observed being exploited in the wild,” it said, addi...