ZeroHour
Canadian Centre for Cyber Securitypublished ()ingested Canadian Centre for Cyber Security

N-able security advisory (AV26-885)

highAdvisory exploited in the wildimportance 66CVE-2026-86218
AI summary · glm-5.3-flash

N-able says CVE-2026-86218 in N-central is exploited in the wild; MSPs must apply hotfix 2026.3.1.14 (2026.3 HF4).

Canadian Centre for Cyber Security advisory AV26-885 covers CVE-2026-86218 in N-able N-central, which the vendor confirms is being exploited in the wild. Versions prior to 2026.3.1.14 are affected, and the fix ships as N-central 2026.3 Hotfix 4. The Cyber Centre urges users and administrators to apply the update promptly.

  • CVE-2026-86218 in N-able N-central confirmed exploited in the wild by the vendor
  • Affected: N-central versions prior to 2026.3.1.14; fix is 2026.3 Hotfix 4
  • CCC advisory AV26-885 urges immediate application of the hotfix
VendorsN-able
ProductsN-central
CountriesCanada

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-86218
Pre-Auth Static Code Injection RCE in N-able N-central (Exploited in the Wild)

CVE-2026-86218 is a static code injection flaw (CWE-96) in N-able's N-central on-premises remote monitoring and management (RMM) platform, carrying a maximum CVSS 4.0 score of 10.0. An unauthenticated, remote attacker triggers it by sending crafted network input to the N-central server that is improperly neutralized and persisted into application-managed code, which the server then executes — no privileges (PR:N) or user interaction (UI:N) are required. Successful exploitation yields full server compromise with high impact on confidentiality, integrity, and availability, and because N-central acts as the management hub for downstream customer endpoints, compromise can expose the entire managed estate. Any organization running an affected N-central release (before 2026.3.1.14) — primarily MSPs and corporate IT departments using N-able RMM — is affected. The flaw is confirmed exploited in the wild: N-able patched it as a zero-day, CISA added it to the KEV catalog on 2026-09-08, and it is the fourth N-central hotfix in five weeks, though no public PoC is known and ransomware use is unknown.

Do: Upgrade N-central to 2026.3.1.14 or later (or apply N-able's hotfix) immediately, as the flaw is in CISA's KEV catalog and BOD 26-04 timelines apply to federal stakeholders. Until patched, remove direct internet exposure of the N-central server (restrict to VPN/management networks via firewall allowlists) since no authentication is needed for exploitation. Because in-the-wild exploitation is confirmed, review internet-facing N-central servers for indicators of compromise such as unexpected processes, unusual child processes of the web service, and new or suspicious accounts.

10.0<1% KEV PoC
  • N-able N-central before 2026.3.1.14
large≈ tens of thousands of deployed/internet-exposed N-central servers (order of magnitude ~10k+), each managing many downstream customer endpoints
Full article76 words · extracted from cyber.gc.ca · click to collapse

Serial Number: AV26-885
Date: September 8, 2026
Updated: September 9, 2026

As of September 6, 2026, N-able is affected by vulnerabilities in the following product:

  • N-central
    • Prior to 2026.3.1.14

N-able indicates that CVE-2026-86218 is being exploited in the wild.

Update 1

On September 8, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-86218 to their Known Exploited Vulnerabilities (KEV) Database.

Update 2

Open-source reporting indicates that CVE-2026-86207 is being exploited in the wild.

The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/n-able-security-advisory-av26-885