This day 02:05 06:05 10:06 14:07 18:08 22:09
⚠ exploit status: CVE-2026-86218 · KEV
Info  2026-09-09 06:05Z · last 4h · 1 findings · glm-5.2:cloud

Threat Brief — 2026-09-09 — N-able RCE confirmed exploited

CISA has confirmed active in-the-wild exploitation of a maximum-severity pre-authentication remote code execution flaw in N-able N-central, tracked as CVE-2026-86218KEV and listed in the KEV catalog. This is the most actionable item today. No other fresh findings were ingested in the last four hours.

Top items

Themes

The N-able N-central flaw underscores a persistent pattern this briefing period: pre-authentication RCE vulnerabilities in management and RMM platforms are being actively exploited before or shortly after vendor disclosure, and CISA KEV listings continue to serve as the most reliable signal that exploitation has moved from theoretical to operational.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db