CVE-2026-86218 | N-able N-central Pre-Authentication Remote Code Execution Vulnerability
N-able N-central pre-auth RCE CVE-2026-86218 (CVSS 10.0) is actively exploited; CISA added it to KEV and a hotfix is available.
CVE-2026-86218 is a critical pre-authentication remote code execution flaw (CWE-96 static code injection) in N-able N-central servers, scored 10.0 CVSS 4.0 by N-able and 9.8 CVSS 3.1 by NIST. N-able fixed it in N-central 2026.3 Hotfix 4 (build 2026.3.1.14) on September 5, 2026, and has already patched hosted NCOD environments. CISA added the CVE to its Known Exploited Vulnerabilities catalog on September 8, 2026, citing evidence of active exploitation, though researchers have not attributed every reported N-central compromise to this flaw. Horizon3 released a NodeZero Rapid Response test to validate exposure and recommends log review for prior compromise.
- Unauthenticated network attackers can execute code on N-central servers without user interaction
- Fixed in N-central 2026.3.1.14; on-premises deployments should upgrade immediately
- CISA KEV addition on September 8, 2026 confirms active exploitation
- Hosted NCOD instances already patched by N-able
- Restrict console access and audit N-central logs for prior compromise
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-86218 | Pre-Auth Static Code Injection RCE in N-able N-central (Exploited in the Wild) CVE-2026-86218 is a static code injection flaw (CWE-96) in N-able's N-central on-premises remote monitoring and management (RMM) platform, carrying a maximum CVSS 4.0 score of 10.0. An unauthenticated, remote attacker triggers it by sending crafted network input to the N-central server that is improperly neutralized and persisted into application-managed code, which the server then executes — no privileges (PR:N) or user interaction (UI:N) are required. Successful exploitation yields full server compromise with high impact on confidentiality, integrity, and availability, and because N-central acts as the management hub for downstream customer endpoints, compromise can expose the entire managed estate. Any organization running an affected N-central release (before 2026.3.1.14) — primarily MSPs and corporate IT departments using N-able RMM — is affected. The flaw is confirmed exploited in the wild: N-able patched it as a zero-day, CISA added it to the KEV catalog on 2026-09-08, and it is the fourth N-central hotfix in five weeks, though no public PoC is known and ransomware use is unknown. Do: Upgrade N-central to 2026.3.1.14 or later (or apply N-able's hotfix) immediately, as the flaw is in CISA's KEV catalog and BOD 26-04 timelines apply to federal stakeholders. Until patched, remove direct internet exposure of the N-central server (restrict to VPN/management networks via firewall allowlists) since no authentication is needed for exploitation. Because in-the-wild exploitation is confirmed, review internet-facing N-central servers for indicators of compromise such as unexpected processes, unusual child processes of the web service, and new or suspicious accounts. | 10.0 | <1% | KEV PoC ×2 |
| large≈ tens of thousands of deployed/internet-exposed N-central servers (order of magnitude ~10k+), each managing many downstream customer endpoints |
Full article511 words · extracted from horizon3.ai · click to collapse
N-able N-central Pre-Authentication Remote Code Execution Vulnerability
CVE-2026-86218 is a critical pre-authentication remote code execution vulnerability affecting N-able N-central. An unauthenticated attacker with network access to a vulnerable N-central server could exploit the vulnerability to execute code without user interaction. N-able assigned it a CVSS 4.0 score of 10.0, while NIST assigned it a CVSS 3.1 score of 9.8. CISA added CVE-2026-86218 to its Known Exploited Vulnerabilities catalog based on evidence of active exploitation.
Technical Details
CVE-2026-86218 affects the N-central server and is remotely exploitable without authentication or user interaction. The official CVE record classifies the vulnerability as CWE-96, Improper Neutralization of Directives in Statically Saved Code, also known as static code injection.
Successful exploitation could allow an attacker to execute code on the N-central server, affecting the confidentiality, integrity, and availability of the system. The vulnerability has low attack complexity and requires no privileges.
CISA has confirmed that CVE-2026-86218 is being exploited. However, public reporting about specific N-central intrusions also involves other recently disclosed vulnerabilities, and researchers have not conclusively attributed every observed compromise to CVE-2026-86218.
Stop Guessing, Start Proving

NodeZero® Proactive Security Platform — Rapid Response
A NodeZero Rapid Response test has been developed to safely validate whether CVE-2026-86218 can be exploited in your environment. The test executes real attack techniques without causing damage, giving teams immediate clarity on exposure.
- Run the Rapid Response test: Launch from the NodeZero platform to determine whether remote code execution is possible
- Patch immediately: Upgrade self-hosted N-central deployments to version 2026.3.1.14
- Re-run the test: Confirm the vulnerability is no longer exploitable after remediation
Affected Versions & Patch
Affected
N-able N-central versions before 2026.3.1.14 are affected.
Fixed
N-able addressed CVE-2026-86218 in N-central 2026.3 Hotfix 4, build 2026.3.1.14. Customers operating on-premises N-central deployments should upgrade immediately.
N-able has already applied the patch to hosted N-central environments, also referred to as NCOD. Customers using hosted instances do not need to take action.
Mitigations
N-able directs customers with on-premises deployments to upgrade to version 2026.3.1.14. The vendor has not identified an alternative remediation in its public release notes.
If an upgrade cannot be completed immediately, restrict access to the N-central console from the public internet and other untrusted networks. This is a risk-reduction measure and does not remediate the vulnerability.
Because exploitation has been reported, organizations should also review N-central accounts, appliance logs, and administrative activity for signs of unauthorized access. Applying the hotfix does not determine whether a system was compromised before it was patched.
Timeline
- September 5, 2026: N-able released N-central 2026.3 Hotfix 4, build 2026.3.1.14, addressing CVE-2026-86218.
- September 6, 2026: CVE-2026-86218 was published.
- September 8, 2026: CISA added CVE-2026-86218 to its Known Exploited Vulnerabilities catalog based on evidence of active exploitation.
- September 15, 2026: Horizon3 released a NodeZero Rapid Response test for CVE-2026-86218.
References
- N-able Security Advisory
- N-able N-central 2026.3 Hotfix 4 Release Notes
- CVE.org Record – CVE-2026-86218
- NIST NVD – CVE-2026-86218
- CISA Adds Four Known Exploited Vulnerabilities to Catalog
- The Hacker News: N-able N-central Pre-Auth RCE Flaw Exploited in the Wild
- Help Net Security: N-able Patches Critical N-central Zero-Day Exploited in the Wild
Text extracted automatically; images, tables and formatting may be missing. Original: https://horizon3.ai/attack-research/vulnerabilities/cve-2026-86218/