• CISA KEV
  • EXPLOITED
  • PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-86218: pre-auth remote code execution in N-able N-central

An unauthenticated attacker with network access can execute arbitrary code on N-able N-central servers. CVE-2026-86218 is a pre-authentication remote code execution vulnerability affecting N-central releases in the 2026.x branch before 2026.3.1.14; the flaw requires only network access (no privileges or user interaction). Exploitation would allow full compromise of affected N-central instances and any data or integrations they manage.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.12928
CWE
CWE-96
KEV DUE DATE
PATCH
Available

DIRAS TAKE

Urgent — CISA added this vulnerability to its Known Exploited Vulnerabilities catalog with a rapid remediation requirement, so apply the vendor fixes or mitigations immediately, prioritizing internet-facing N-central instances.

What is CVE-2026-86218?

An unauthenticated attacker with network access can execute arbitrary code on N-able N-central servers. CVE-2026-86218 is a pre-authentication remote code execution vulnerability affecting N-central releases in the 2026.x branch before 2026.3.1.14; the flaw requires only network access (no privileges or user interaction). Exploitation would allow full compromise of affected N-central instances and any data or integrations they manage.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of N-able N-central are affected?

BRANCHAFFECTEDFIXED
2026.xbefore 2026.3.1.142026.3.1.14

Is CVE-2026-86218 being exploited?

CISA added CVE-2026-86218 to the Known Exploited Vulnerabilities catalog on 2026-09-08, and U.S. federal agencies must remediate by 2026-09-11. Public exploit code is available.

How to fix CVE-2026-86218

  1. Apply the vendor update to N-central 2026.3.1.14.
  2. If you cannot immediately patch, follow N-able’s mitigation guidance to restrict network exposure and access to N-central.
  3. Restrict management interfaces to trusted networks and VPNs; block unnecessary ports at the perimeter.
  4. Monitor N-central logs and endpoint telemetry for suspicious activity and indicators of compromise.

Frequently asked questions

Is CVE-2026-86218 being actively exploited?

CVE-2026-86218 affects N-central; CISA added it to the Known Exploited Vulnerabilities catalog on 2026-09-08 and public exploit code is available.

Which N-central versions are affected by CVE-2026-86218?

N-central releases in the 2026.x branch before 2026.3.1.14 are affected.

Is there a patch for CVE-2026-86218?

Yes. N-able published a fix; update N-central to version 2026.3.1.14.

Does CVE-2026-86218 require authentication?

No. The vulnerability is pre-authentication and can be exploited over the network without valid credentials.

References