CISA added CVE-2026-86218, a critical pre-authentication remote code execution flaw in N-able N-central, to its Known Exploited Vulnerabilities catalog on 2026-09-08 with a three-day remediation deadline.
What Is It
CVE-2026-86218 is a static code injection vulnerability (CWE-96) in N-able N-central. CISA tracks it as "N-able N-central Static Code Injection Vulnerability" and describes it as allowing pre-authentication remote code execution. The NVD record states plainly that N-central is vulnerable to pre-auth RCE in all versions before 2026.3.1.14.
NVD assigns a CVSS 3.1 base score of 9.8 (CRITICAL) with vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The vendor-supplied CVSS 4.0 score is a maximum 10.0, reflecting high confidentiality, integrity, and availability impact on both the vulnerable and subsequent systems.
Why It Matters
CISA's SSVC assessment marks exploitation as active, automatable as yes, and technical impact as total. That combination, network-reachable, no privileges, no user interaction, and automatable at scale, matches the profile of vulnerabilities that have historically drawn mass scanning soon after disclosure, though how quickly that materializes here is not yet established.
The KEV entry also flags Forensic Triage: Yes, meaning affected organizations are expected to determine whether compromise already occurred, not just patch and move on. Known ransomware campaign use is listed as Unknown.
What's Vulnerable
- N-able N-central, all versions before 2026.3.1.14
- Explicitly enumerated in NVD configurations: N-central 2026.3 base release, plus Hotfix 1, Hotfix 2, and Hotfix 3
Hotfixes 1 through 3 for the 2026.3 branch do not remediate this issue.
Patch Status
N-able published Hotfix 4 for N-central 2026.3 addressing CVE-2026-86218. The fixed version is 2026.3.1.14.
CISA's required action, with a due date of 2026-09-11: apply mitigations per vendor instructions in compliance with BOD 26-04 (Prioritizing Security Updates Based on Risk) and CISA's Forensics Triage Requirements. Follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure.
Sources
- N-able Status; N-central 2026.3 Hotfix 4 (CVE-2026-86218)
- N-able Security Advisory; CVE-2026-86218 Pre-Authentication RCE
- NVD, CVE-2026-86218
- CISA Known Exploited Vulnerabilities Catalog; CVE-2026-86218
- CISA BOD 26-04; Prioritizing Security Updates Based on Risk
- CISA BOD 26-04 Implementation Guidance / Forensics Triage Requirements