← Vulnerability feed

Vulnerability record · CVE-2026-86218 · published 6 September 2026

CVE-2026-86218: N-able N-central pre-auth remote code execution via static code injection

N Able · N Central

N-central contains a static code injection flaw (CWE-96) that allows remote code execution before authentication. The record states the issue affects N-central before 2026.3.1.14, and CISA added it to the Known Exploited Vulnerabilities catalog, so it is being exploited in the wild. Because it is pre-auth and network reachable, any exposed instance is at immediate risk.

10.0 CVSS 4.0 Critical CISA KEV since 8 Sep 2026 EPSS 13% · top 3.8% CWE-96 · CWE-96
10.0CVSS 4.0 base score
13%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
2References
9 Sep 2026Last modified by NVD

Description

N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

critical priorityPre-auth network-reachable remote code execution with a CVSS 4.0 score of 10.0 and confirmed exploitation via CISA KEV.

What it is

N-central contains a static code injection flaw (CWE-96) that allows remote code execution before authentication. The record states the issue affects N-central before 2026.3.1.14, and CISA added it to the Known Exploited Vulnerabilities catalog, so it is being exploited in the wild. Because it is pre-auth and network reachable, any exposed instance is at immediate risk.

Impact

An unauthenticated attacker can execute arbitrary code on the N-central server, gaining full control of the host and any managed endpoints or credentials it holds. CVSS 4.0 scores it 10.0 with high confidentiality, integrity and availability impact across the vulnerable and subsequent systems.

Attack surface

Reachable over the network with no authentication and no user interaction required, per the CVSS vector (AV:N/PR:N/UI:N). The description does not specify the exact endpoint or interface, so defenders should treat all network-exposed N-central services as in scope.

Exploitation

CISA added this to the KEV catalog on 2026-09-08 with a remediation due date of 2026-09-11, indicating known exploitation. EPSS is low (0.00744, 53rd percentile), so the KEV listing is the stronger signal. No ransomware campaign use is documented.

What to do

  • Upgrade N-central to 2026.3.1.14 or later immediately, per the vendor advisory.
  • If patching cannot be completed before the CISA due date, remove internet exposure of N-central or discontinue use until mitigations are applied.
  • Apply any vendor-supplied mitigations or workarounds in the N-able security advisory.
  • Restrict management and agent-facing ports to trusted networks and place N-central behind a hardened reverse proxy or VPN.
  • Rotate credentials and certificates stored or managed by N-central after remediation, assuming possible compromise.

Detection

  • Review N-central and web server logs for unexpected POST or request patterns to application endpoints from unauthenticated sources.
  • Hunt for anomalous child processes spawned by the N-central service (web/app server, Java, or IIS worker processes).
  • Monitor for new or modified files in N-central web-accessible directories and for outbound connections from the N-central host.
  • Check for unexpected scheduled tasks, new local accounts, or persistence mechanisms on the N-central server.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2026-86218 to the Known Exploited Vulnerabilities catalog on 8 September 2026 as "N-able N-central Static Code Injection Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 11 September 2026.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-86218 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.4CVE-2025-8875N-able N-central deserialization of untrusted data allows code executionN-able N-central contains a deserialization of untrusted data flaw (CWE-502) that permits code execution. It affects N-central versions before 2025.3…KEVEPSS 1.9%analysed9.4CVE-2025-8876N-able N-central improper input validation leads to OS command injectionN-able N-central before 2025.3.1 fails to properly validate input, allowing OS command injection. Because N-central is a remote monitoring and manage…KEVEPSS 3.4%analysed8.2CVE-2026-18577N-able N-central incomplete patch enables auth bypass and account takeoverAn incomplete fix for CVE-2026-18556 leaves an alternate-path authentication bypass in N-able N-central through version 2026.3.1. Because the origina…KEVEPSS 15%analysed8.2CVE-2026-18556N-able N-central authentication bypass via alternate pathN-able N-central contains an authentication bypass (CWE-288) that lets an attacker reach protected functionality through an alternate path or channel…KEVEPSS 7.9%analysed10.0CVE-2025-11367N-able n-central deserialization of untrusted data vulnerabilityThe N-central Software Probe < 2025.4 is vulnerable to Remote Code Execution via deserializationEPSS 0.58%9.8CVE-2024-28200N-able n-central authentication bypass via alternate path vulnerabilityThe N-central server is vulnerable to an authentication bypass of the user interface. This vulnerability is present in all deployments of N-central p…EPSS 1.9%9.8CVE-2023-47132N-able n-central improper privilege management vulnerabilityAn issue discovered in N-able N-central before 2023.6 and earlier allows attackers to gain escalated privileges via API calls.EPSS 0.55%9.4CVE-2025-11366N-able n-central path traversal vulnerabilityN-central < 2025.4 is vulnerable to authentication bypass via path traversalEPSS 0.56%

Source: NIST National Vulnerability Database (record CVE-2026-86218), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.