N-able N-central Pre-Auth RCE Flaw Exploited in the Wild
A critical remote code execution vulnerability (CVE-2026-86218) in N-able N-central has been actively exploited in the wild, prompting CISA to require FCEB agencies to patch it. The vulnerability allows attackers to execute code without authentication, and N-able is investigating the exploitation.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a maximum-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 11, 2026. The vulnerability, identified as CVE-2026-86218 (CVSS score: 10.0), is a static code injection issue. Huntress Labs initiated an investigation after discovering a compromised, fully patched N-central production environment on September 4, 2026. However, it remains uncertain whether the intrusion involved CVE-2026-86218 or two other patched vulnerabilities (CVE-2026-86206 and CVE-2026-86207) – CVE-2026-86206 and CVE-2026-86207 can be chained together to allow a remote unauthenticated attacker to bypass authentication and create a new attacker-controlled System Administrator account on an affected server, as reported by Rapid7’s Stephen Fewer. N-able released a hotfix (2026.3 Hotfix 4) on September 5, 2026, and a separate hotfix (2026.3 Hotfix 3) to address the other vulnerabilities on the same day. N-able stated that CVE-2026-86218 has been observed being exploited in the wild and is actively investigating the matter, taking additional steps to protect customer environments. Due to limited logging available directly on the appliance, it’s difficult to determine which specific exploit was used.
