N-able has released a security update addressing CVE-2026-86218, a critical pre-authentication Remote Code Execution (RCE) vulnerability in its N-central remote monitoring and management platform. The flaw can allow an unauthenticated remote attacker to execute code on an affected N-central server. The vulnerability carries a CVSS v4.0 score of 10.0 (Critical) and requires no user interaction or prior authentication. CVE-2026-86218 affects N-central versions earlier than 2026.3.1.14. The vulnerability is classified as CWE-96 (Improper Neutralization of Directives in Statically Saved Code). Its pre-authentication nature means an attacker does not need valid credentials before attempting exploitation. The CVSS vector indicates network-based exploitation with low complexity, no privileges, and no user interaction, with high potential impact to confidentiality, integrity, and availability. N-able has not publicly disclosed detailed exploitation mechanics or confirmed exploitation in the wild. Because N-central provides centralized management capabilities for endpoints and customer environments, successful compromise of an exposed server could provide attackers with a significant foothold into managed infrastructure.
A new Linux malware bot named Tengu has been identified as a stealthy threat capable of turning compromised Linux servers, embedded systems, and IoT-adjacent devices into DDoS atta...
The Linux kernel development team has officially ended support for the Linux Kernel 7.1 branch, meaning it will no longer receive security patches, bug fixes, or maintenance update...
Threat actors are abusing legitimate Google services to conceal phishing campaigns designed to steal corporate credentials and, in some cases, install remote-access software. The c...