CSIRT Italia said N-able’s N-central has an actively exploited flaw, CVE-2026-86218, and N-able’s update fixes three issues in the remote monitoring and management platform. At the same time, Ivanti shipped September patches for Neurons for ITSM, Sentry, and Endpoint Manager Mobile (EPMM), including several critical remote code execution and authentication-bypass bugs.
CSIRT Italia says the N-central bug lets a remote attacker send crafted HTTP or HTTPS requests to an exposed server port, inject directives into files the platform later trusts, and have those directives executed when the file is processed. In plain terms, the management console can be made to run attacker code, so the blast radius is the systems it administers, not just the box running N-central.
For operators of remote management and enterprise admin tools, the split matters: N-central is now an active response case, while the Ivanti fixes are routine patch-cycle work. If a console sits between you and a fleet, a single web flaw can turn into access to everything it manages, and the reporting here makes N-central the one with the most immediate pressure.