DIRAS TAKE
Urgent — CISA added this vulnerability to its Known Exploited Vulnerabilities catalog with a rapid remediation requirement, so apply the vendor fixes or mitigations immediately, prioritizing internet-facing N-central instances.
What is CVE-2026-86218?
An unauthenticated attacker with network access can execute arbitrary code on N-able N-central servers. CVE-2026-86218 is a pre-authentication remote code execution vulnerability affecting N-central releases in the 2026.x branch before 2026.3.1.14; the flaw requires only network access (no privileges or user interaction). Exploitation would allow full compromise of affected N-central instances and any data or integrations they manage.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of N-able N-central are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 2026.x | before 2026.3.1.14 | 2026.3.1.14 |
Is CVE-2026-86218 being exploited?
CISA added CVE-2026-86218 to the Known Exploited Vulnerabilities catalog on 2026-09-08, and U.S. federal agencies must remediate by 2026-09-11. Public exploit code is available.
How to fix CVE-2026-86218
- Apply the vendor update to N-central 2026.3.1.14.
- If you cannot immediately patch, follow N-able’s mitigation guidance to restrict network exposure and access to N-central.
- Restrict management interfaces to trusted networks and VPNs; block unnecessary ports at the perimeter.
- Monitor N-central logs and endpoint telemetry for suspicious activity and indicators of compromise.
Frequently asked questions
Is CVE-2026-86218 being actively exploited?
CVE-2026-86218 affects N-central; CISA added it to the Known Exploited Vulnerabilities catalog on 2026-09-08 and public exploit code is available.
Which N-central versions are affected by CVE-2026-86218?
N-central releases in the 2026.x branch before 2026.3.1.14 are affected.
Is there a patch for CVE-2026-86218?
Yes. N-able published a fix; update N-central to version 2026.3.1.14.
Does CVE-2026-86218 require authentication?
No. The vulnerability is pre-authentication and can be exploited over the network without valid credentials.
References
- nvd.nist.gov/vuln/detail/CVE-2026-86218
- cve.org/CVERecord?id=CVE-2026-86218
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-86218
- me.n-able.com/s/security-advisory/aArVy0000002Ld3KAE/cve202686218-preauthentication-remote-code-execution
- All N-able CVEs on CVE Radar
- CVEs published in September 2026