NCSC-2026-0342 [1.01] [H/H] Kwetsbaarheid verholpen in N-central van N-able
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
N-able heeft een kwetsbaarheid verholpen in N-central versies eerder dan 2026.3.1.14. De kwetsbaarheid betreft een pre-authenticatie remote code execution flaw. Een aanvaller kan hierdoor op afstand willekeurige code uitvoeren op het getroffen systeem zonder enige vorm van authenticatie. Alle installaties die draaien op de kwetsbare versies van N-central zijn getroffen. Klanten met een on-premises N-central-omgeving wordt geadviseerd zo snel mogelijk te upgraden naar N-central 2026.3 HF4. Voor gebruikers van een gehoste N-central-instantie (NCOD) zijn de patches al toegepast. Er is op dit moment geen actie vereist. N-able meldt dat pogingen tot exploitatie zijn waargenomen, volg het advies van N-able op om onderzoek te doen naar IoC's. UPDATE N-able meldt dat bij klanten succesvolle exploitatie van de kwetsbaarheid is waargenomen. N-able onderzoekt de incidenten verder en werkt rechtstreeks samen met klanten die verdachte activiteiten melden. Volg het advies N-able op, dat staat beschreven in de blog. EINDE UPDATE
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0342
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation confirmedCVE-2026-86218Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 53% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-86218 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownexploitedN-able security advisory (AV26-885) – Update 2cccs
- criticalexploited[UPDATE] [kritisch] N-able N-Central: Mehrere Schwachstellen ermöglichen Offenlegung von Informationencert-bund
- highexploitedCISA Adds Four Known Exploited Vulnerabilities to Catalogcisa
- criticalexploitedCVE-2026-86218: N-able N-central Static Code Injection Vulnerabilitycisa-kev
- unknownexploitedNCSC-2026-0342 [1.00] [H/H] Kwetsbaarheid verholpen in N-central van N-ablencsc-nl
- criticalexploitedCVE-2026-86218: N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: befo…nvd
More from NCSC-NL Advisories
- unknownNCSC-2026-0076 [1.03] [H/H] Kwetsbaarheden verholpen in Cisco Secure Firewall Management Center2026-09-12
- unknownNCSC-2026-0367 [1.00] [H/H] Kwetsbaarheid verholpen in GitLab Community en Enterprise Editions2026-09-12
- unknownNCSC-2026-0271 [1.01] [M/H] Kwetsbaarheid verholpen in Cisco Secure Firewall Management Center2026-09-11
- unknownNCSC-2026-0076 [1.02] [H/H] Kwetsbaarheden verholpen in Cisco Secure Firewall Management Center2026-09-11
- unknownNCSC-2026-0366 [1.00] [M/H] Kwetsbaarheden verholpen in Arista EOS2026-09-11