Published: · Region: Global · Category: cyber

Actively exploited Windows zero‑days and N‑able flaw expose high‑value IT systems

Attackers are already exploiting two new Windows zero‑day vulnerabilities that Microsoft fixed in a record patch batch of 974 flaws, while N‑able says a CVSS 10.0 bug in its N‑central remote‑management tool is also being abused. Both give intruders a route to high‑level control of core IT systems that support business and government networks.

Two newly patched Windows vulnerabilities and a critical flaw in a widely used remote‑management platform are being exploited in real‑world attacks, putting extra strain on defenders who rely on both products to run their networks.

Microsoft has confirmed that two Windows vulnerabilities it fixed in its latest monthly release are already under active attack. Both flaws let an authorized attacker elevate their local privileges to SYSTEM, the highest level of control in Windows. They were patched as part of a record group of 974 vulnerabilities, an unusually large number that can make it harder for administrators to pick out the most urgent issues.

Separately, N‑able has warned that a vulnerability tracked as CVE‑2026‑86218 in its N‑central remote monitoring and management product is being exploited. The bug has the maximum CVSS severity score of 10.0 and allows remote code execution before authentication. In practice, that means someone who can reach a vulnerable N‑central system over the network can run their own code without first logging in.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added both the Windows zero‑days and the N‑central flaw to its Known Exploited Vulnerabilities catalog. That list is reserved for security bugs that are already being used in attacks, and it is meant to guide federal agencies and critical‑infrastructure operators on what to fix first.

For users inside corporate or public‑sector networks, the Windows bugs matter because they turn minor footholds into full control. Once attackers get any kind of local access—through a phishing email, a weak password, or another vulnerability—these privilege‑escalation flaws let them promote themselves to SYSTEM level, disable protections, and move to more sensitive machines.

The N‑central issue is especially serious because of the software’s role. Remote monitoring and management platforms like N‑central sit at the center of IT operations, giving administrators a way to control many client systems at once. If an attacker exploits a pre‑authentication remote‑code‑execution flaw there, they don’t just compromise one computer; they potentially gain a jumping‑off point into every network managed through that installation.

Security company Huntress has said it is investigating a separate compromise of an N‑central environment where the exact exploit technique hasn’t been confirmed. That raises the possibility that more than one method of attack may be in play against the platform, and it reinforces the need for organizations running N‑central to treat it as a high‑value target in its own right.

The combination of a record‑size Microsoft patch release and active exploitation of high‑impact bugs in both Windows and N‑central puts IT leaders in a difficult spot. They need to deploy critical Windows fixes quickly while also locking down or patching the very remote‑management tools they depend on to run updates. Because those tools touch many downstream systems, a single successful intrusion can spread widely.

The clearest indicators to watch now are how fast organizations apply the Windows patches for the two zero‑days, how many exposed N‑central instances remain unpatched, and whether new incidents link ransomware or espionage operations back to these vulnerabilities. Any further guidance from CISA about specific attackers using these bugs, or emergency instructions to U.S. federal agencies, would signal how severe governments judge the current wave of exploitation to be.

Sources