# Active attacks on Windows flaws and N‑able N‑central bug push core IT tools into hackers’ sights

*Wednesday, September 9, 2026 at 6:19 AM UTC — Hamer Intelligence Services Desk*

**Published**: 2026-09-09T06:19:43.164Z (2h ago)
**Category**: cyber | **Region**: Global
**Importance**: 8/10
**Sources**: OSINT
**Permalink**: https://hamerintel.com/data/articles/17340.md
**Source**: https://hamerintel.com/summaries

---

**Deck**: Two Windows zero‑day vulnerabilities and a CVSS 10.0 remote‑code flaw in N‑able’s N‑central platform are being exploited in the wild, security researchers and vendors report.

Attackers are exploiting serious weaknesses at the heart of many corporate and service‑provider networks. Two separate Windows zero‑day vulnerabilities are under active attack even as Microsoft rolls out patches for a record 974 flaws, while N‑able has confirmed that a critical pre‑authentication remote‑code execution bug in its N‑central management platform is also being used in the wild.

According to The Hacker News, Microsoft’s latest updates include fixes for two Windows bugs that were already being exploited. Both allow authorized attackers to locally elevate their privileges to SYSTEM, the highest level of control on a Windows machine. Once a threat actor has any foothold on a device, these flaws can help them disable defenses, move laterally, and gain deep access.

At the same time, N‑able says CVE‑2026‑86218, a vulnerability in its N‑central product with a maximum CVSS score of 10.0, enables remote code execution without authentication. That means an attacker can potentially compromise an N‑central server from the outside without valid credentials.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the N‑central flaw, and the two Windows zero‑days, to its Known Exploited Vulnerabilities catalog. Security firm Huntress is also investigating a separate N‑central compromise where the exact exploit path hasn’t yet been confirmed.

For organizations that run Windows at scale, the two zero‑days raise the stakes of any existing low‑privilege compromise. For those that rely on N‑central, the risk is broader still: a successful hit on one management server can open up many connected customer systems.

Defenders now face pressure to deploy Microsoft’s patches quickly while also identifying and securing any exposed N‑central instances. How fast enterprises and service providers can lock down these core tools will determine whether the current wave of exploitation remains limited or turns into a chain of larger breaches.

Key indicators to follow include any public disclosure of major incidents linked to the N‑central bug, updates from CISA that tighten patching requirements, and threat intelligence tying the Windows zero‑days to specific attack groups or campaigns.
