N-able N-central Pre-Auth RCE Flaw Exploited in the Wild
Reported exploitedN-centralOur summary
CISA has added CVE-2026-86218 to its Known Exploited Vulnerabilities catalog, mandating that federal agencies patch N-able N-central by September 11, 2026. This maximum-severity flaw (CVSS 10.0) enables pre-authentication remote code execution via static code injection. The vendor released a fix in N-central 2026.3 Hotfix 4 on September 5, 2026, following reports of active exploitation and customer compromises investigated by Huntress.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.