Exploitation timeline
Threadlinqs has recorded 5 N-able CVEs published between and . The busiest month was 2026-09 (3 new CVEs). 2 of them (40%) are listed in CISA KEV, which means exploitation in the wild has been confirmed.
Most exploited vulnerabilities
Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 5 of 5 tracked N-able CVEs.
- CVE-2026-18577high 8.2KEVEPSS 1.5%
- CVE-2026-86218critical 10KEVEPSS 0.7%
- CVE-2026-86207high 7.7EPSS 0.3%
- CVE-2026-86206medium 6.9EPSS 0.3%
- CVE-2026-18556high 8.2EPSS 0.3%
Products affected
Threadlinqs normalises CPE and CNA product records across all 5 CVEs; 1 distinct N-able product is affected. The most frequently affected:
- N-central 5 CVEs
Threat activity
7 tracked threat campaigns reference N-able products or exploit N-able CVEs:
- Multi-Stage Abuse of Legitimate Remote Access Tools (ConnectWise, N-Able, SimpleHelp, Datto RMM, GoTo) by Initial Access BrokersHIGH
- CVE-2026-86218 — Unauthenticated Pre-Auth Remote Code Execution in N-able N-central (Active Exploitation, CISA KEV)CRITICAL
- N-able N-central Authentication Bypass Flaws (CVE-2026-18556, CVE-2026-18577) Actively Exploited for Admin Access and Cloudflare Tunnel PersistenceHIGH
- N-able N-central Authentication Bypass (CVE-2026-18577) Actively Exploited for Admin TakeoverCRITICAL
- Evolution of Remote Access Tool (RAT/RMM) Abuse: Multi-Stage Chaining of ConnectWise, GoTo, Datto, SimpleHelp, N-able, and Heartbeat RMMEDIUM
- MuddyWater APT (Iran MOIS-linked, G0069) abuses legitimate RMM tools, VBA macro loaders, and Rust-compiled payloads in ongoing global espionage campaignHIGH
- The Remote Access Blind Spot: Acronis TRU Analysis of RMM Tool Proliferation and Abuse Risk in SMB EnvironmentsMEDIUM
Threat actors targeting N-able
Named threat actors attributed to campaigns that involve N-able products or CVEs, with the number of linked campaigns:
How to prioritise N-able patching
This order follows the data Threadlinqs holds for N-able, not a generic severity checklist:
- 2 of 5 N-able CVEs (40%) are in CISA KEV: treat them as actively exploited and remediate them first, starting with CVE-2026-18577, CVE-2026-86218.
- Outside KEV, the highest EPSS scores are CVE-2026-86207 (0.3%), CVE-2026-86206 (0.3%), CVE-2026-18556 (0.3%).
- 1 CVE scores Critical and 3 High on CVSS v3 (maximum 10, average 8.2); sequence these after KEV and high-EPSS items.
- 1 CVE has a public exploit or proof of concept recorded, which shortens the time from disclosure to attack.
About this data
Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.