חזרה לפיד
newsמקור: The Hacker News9.9.2026

פרצת RCE ב-N-able N-central מנוצלת בפועל

N-able N-central Pre-Auth RCE Flaw Exploited in the Wild

פרצת RCE ב-N-able N-central מנוצלת בפועל

◆ סיכום AI

סוכנות CISA הוסיפה פרצת אבטחה קריטית (CVE-2026-86218) במוצר N-able N-central לקטלוג ה-KEV שלה. הפרצה, בעלת ציון CVSS של 10.0, מאפשרת RCE ללא אימות (Pre-Auth) ונמצאת בשימוש פעיל על ידי תוקפים. סוכנויות ממשלתיות נדרשות לתקן אותה עד ספטמבר 2026, מה שמדגיש את חומרתה ודחיפות הטיפול בה.

# מהמקור

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 11, 2026. The vulnerability in question is CVE-2026-86218 (CVSS score: 10.0), which has been described as a

#rce#cve#supply-chain-security#vulnerability
קרא במקור