Published: · Region: Global · Category: cyber

Actively exploited Windows and N‑able flaws give attackers SYSTEM access and pre‑auth remote code execution

Two newly patched Windows zero‑day vulnerabilities and a separate critical flaw in N‑able’s N‑central platform are already being exploited, allowing attackers to gain SYSTEM‑level control on Windows machines and pre‑authentication remote code execution on N‑central servers, according to security reports and U.S. cyber authorities.

Attackers are already abusing two freshly patched Windows zero‑day vulnerabilities and a separate critical bug in N‑able’s N‑central platform, exposing organisations to compromise even as fixes become available.

Security reports say Microsoft has addressed two Windows flaws that were being exploited before patches were released. Both vulnerabilities have been added to the U.S. Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities (KEV) catalogue.

Each of the Windows bugs allows an authorised attacker to elevate privileges locally to SYSTEM, the highest level of access on a Windows machine. In practice, that means a low‑level foothold obtained through phishing or another vulnerability can quickly be turned into full control of a device.

At the same time, N‑able has disclosed that CVE‑2026‑86218, a vulnerability in its N‑central remote monitoring and management product, is also being exploited in the wild. The flaw carries a maximum CVSS severity score of 10.0 and enables pre‑authentication remote code execution.

Because the N‑central bug is pre‑auth, an attacker doesn’t need valid credentials to take over a vulnerable N‑central server. In many environments, that server is tightly connected to large numbers of client systems, making it a potential single point of failure.

The addition of these issues to CISA’s KEV list signals that there is credible evidence of real‑world exploitation, not just lab demonstrations. For U.S. federal agencies, KEV inclusion triggers binding deadlines to apply patches. For the private sector, it acts as a priority list of vulnerabilities that attackers are already using.

For enterprise IT teams, the Windows zero‑days mean privilege‑escalation bugs must be treated as more than routine patching items. Combined with other exploits, they can help intruders disable security software, move laterally and deploy ransomware or steal data.

For organisations that rely on N‑able’s N‑central, the pre‑auth remote code execution flaw raises the stakes further. Compromise of a single management console could open a path into many downstream networks tied into that system.

The broader lesson is that tools used to manage and secure systems are themselves high‑value targets. When attackers can turn those tools against their operators, the impact extends well beyond one server to entire fleets of connected machines.

Signals to monitor include how quickly patches for these flaws are deployed across large Windows environments, incident reports from users of N‑central, and any follow‑up advisories from CISA or major security firms linking these vulnerabilities to specific attacker groups.

Sources