Vulnerability record · CVE-2026-86218 · published 6 September 2026
CVE-2026-86218: N-able N-central pre-auth remote code execution via static code injection
N Able · N Central
N-central contains a static code injection flaw (CWE-96) that allows remote code execution before authentication. The record states the issue affects N-central before 2026.3.1.14, and CISA added it to the Known Exploited Vulnerabilities catalog, so it is being exploited in the wild. Because it is pre-auth and network reachable, any exposed instance is at immediate risk.
Description
N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Automated analysis
critical priorityPre-auth network-reachable remote code execution with a CVSS 4.0 score of 10.0 and confirmed exploitation via CISA KEV.
What it is
N-central contains a static code injection flaw (CWE-96) that allows remote code execution before authentication. The record states the issue affects N-central before 2026.3.1.14, and CISA added it to the Known Exploited Vulnerabilities catalog, so it is being exploited in the wild. Because it is pre-auth and network reachable, any exposed instance is at immediate risk.
Impact
An unauthenticated attacker can execute arbitrary code on the N-central server, gaining full control of the host and any managed endpoints or credentials it holds. CVSS 4.0 scores it 10.0 with high confidentiality, integrity and availability impact across the vulnerable and subsequent systems.
Attack surface
Reachable over the network with no authentication and no user interaction required, per the CVSS vector (AV:N/PR:N/UI:N). The description does not specify the exact endpoint or interface, so defenders should treat all network-exposed N-central services as in scope.
Exploitation
CISA added this to the KEV catalog on 2026-09-08 with a remediation due date of 2026-09-11, indicating known exploitation. EPSS is low (0.00744, 53rd percentile), so the KEV listing is the stronger signal. No ransomware campaign use is documented.
What to do
- Upgrade N-central to 2026.3.1.14 or later immediately, per the vendor advisory.
- If patching cannot be completed before the CISA due date, remove internet exposure of N-central or discontinue use until mitigations are applied.
- Apply any vendor-supplied mitigations or workarounds in the N-able security advisory.
- Restrict management and agent-facing ports to trusted networks and place N-central behind a hardened reverse proxy or VPN.
- Rotate credentials and certificates stored or managed by N-central after remediation, assuming possible compromise.
Detection
- Review N-central and web server logs for unexpected POST or request patterns to application endpoints from unauthenticated sources.
- Hunt for anomalous child processes spawned by the N-central service (web/app server, Java, or IIS worker processes).
- Monitor for new or modified files in N-central web-accessible directories and for outbound connections from the N-central host.
- Check for unexpected scheduled tasks, new local accounts, or persistence mechanisms on the N-central server.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2026-86218 to the Known Exploited Vulnerabilities catalog on 8 September 2026 as "N-able N-central Static Code Injection Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 11 September 2026.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2026-86218 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-86218), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.