Vendor

N-able

As of , 5 N-able vulnerabilities are on CISA's list of exploited vulnerabilities; 3 were added in 2026. Patch first: CVE-2026-86218.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2026-86218Static Code InjectionN-able N-centralPatch nowForensic triage required by CISA0.13
2CVE-2026-18577Authentication Bypass Using an Alternate Path or ChannelN-able N-centralPatch nowForensic triage required by CISA0.15
3CVE-2026-18556Authentication Bypass Using an Alternate Path or ChannelN-able N-centralPatch nowForensic triage required by CISA0.08
4CVE-2025-8876Command InjectionN-able N-CentralPatch soon0.03
5CVE-2025-8875Insecure DeserializationN-able N-CentralPatch soon0.02

Added each year

1232025: 2220252026: 332026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20252
20263

Used in ransomware