Cyber & AI intelligence
Wasteland.
Briefs indexed2597
Issues28
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-86218 2026-09-08

CVE-2026-86218: Pre-Auth RCE in N-able N-central Lands on CISA KEV

"CISA added CVE-2026-86218, a critical pre-authentication remote code execution flaw in N-able N-central, to its Known Exploited Vulnerabilities catalog on 2026-09-08 with a three-day remediation deadline."

CISA added CVE-2026-86218, a critical pre-authentication remote code execution flaw in N-able N-central, to its Known Exploited Vulnerabilities catalog on 2026-09-08 with a three-day remediation deadline.

What Is It

CVE-2026-86218 is a static code injection vulnerability (CWE-96) in N-able N-central. CISA tracks it as "N-able N-central Static Code Injection Vulnerability" and describes it as allowing pre-authentication remote code execution. The NVD record states plainly that N-central is vulnerable to pre-auth RCE in all versions before 2026.3.1.14.

NVD assigns a CVSS 3.1 base score of 9.8 (CRITICAL) with vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The vendor-supplied CVSS 4.0 score is a maximum 10.0, reflecting high confidentiality, integrity, and availability impact on both the vulnerable and subsequent systems.

Why It Matters

CISA's SSVC assessment marks exploitation as active, automatable as yes, and technical impact as total. That combination, network-reachable, no privileges, no user interaction, and automatable at scale, matches the profile of vulnerabilities that have historically drawn mass scanning soon after disclosure, though how quickly that materializes here is not yet established.

The KEV entry also flags Forensic Triage: Yes, meaning affected organizations are expected to determine whether compromise already occurred, not just patch and move on. Known ransomware campaign use is listed as Unknown.

What's Vulnerable

Hotfixes 1 through 3 for the 2026.3 branch do not remediate this issue.

Patch Status

N-able published Hotfix 4 for N-central 2026.3 addressing CVE-2026-86218. The fixed version is 2026.3.1.14.

CISA's required action, with a due date of 2026-09-11: apply mitigations per vendor instructions in compliance with BOD 26-04 (Prioritizing Security Updates Based on Risk) and CISA's Forensics Triage Requirements. Follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure.

Sources