πŸ”΄ CVE-2026-86218

CVE-2026-86218 is a critical (CVSS 10.0) pre-authentication remote code execution vulnerability in N-able N-central, an RMM platform widely used by MSPs. Unauthenticated remote attackers can achieve full code execution on the server over the network with no user interaction, and the flaw is confirmed to be actively exploited in the wild (CISA KEV listed). This is a textbook T1190 initial access vulnerability granting complete server takeover.

← Back to Overview
HIGH_RISK
Risk Level
10.0
CVSS Score
NETWORK
Attack Vector
Initial Access
ATT&CK Tactic
T1190 β€” Exploit Public-Facing Application
ATT&CK Technique
HIGH
Deployment Risk
No
Ransomware

πŸ“‹ Vulnerability Details

Data Source: CIRCL

Confidence: HIGH

Exploitation Method: DIRECT_NETWORK

CVE Published: 2026-09-06

Added to CISA KEV: 2026-09-08 2 DAYS BETWEEN CVE AND KEV

🎯 Recommendations:

πŸ” Web Intelligence (Kagi Β· 2026-09-14)

Summary

CVE-2026-86218 is a critical-severity, pre-authentication remote code execution (RCE) vulnerability affecting the N-able N-central server management platform. The flaw allows unauthenticated remote attackers to execute arbitrary code on an affected server, effectively granting them full administrative control over the system. This vulnerability is highly significant because N-central is frequently used by Managed Service Providers (MSPs) to manage the IT environments of numerous downstream customers, making it a high-value target that can serve as a conduit for wide-scale supply chain attacks.

Exploitation

  • Active Exploitation: The vulnerability is being actively exploited in the wild, leading to its inclusion in the CISA Known Exploited Vulnerabilities (KEV) catalog [2].
  • Threat Actors: While specific advanced persistent threat (APT) groups have not been publicly named in relation to this specific campaign as of September 14, 2026, the nature of the exploit and its inclusion in the CISA KEV suggest significant interest from sophisticated threat actors.
  • Proof-of-Concept/Exploit Tools: While functional exploit code is being leveraged by attackers in the wild, widespread public disclosure of weaponized exploit kits has been limited to mitigate further unauthorized use [1].
  • Attack Prerequisites:
- Authentication: None required (pre-authentication) [3]. - Accessibility: The attack is performed over the network, primarily targeting internet-facing N-central instances. - User Interaction: None required.

Affected Products & Patches

  • Affected Versions: All N-central versions prior to 2026.3.1.14 [4].
  • Patch/Hotfix: N-able has released an emergency security hotfix, version 2026.3.1.14 (included in Hotfix 4), to address the vulnerability [3].
  • Mitigations: There are no known workarounds for this vulnerability; upgrading to the patched version is the only effective defense. Federal agencies and other high-security entities were under mandate to apply the patch by September 11, 2026 [2].

Impact

  • Access/Capabilities: Successful exploitation grants attackers arbitrary code execution with the privileges of the N-central service, allowing for complete system takeover, data exfiltration, and the deployment of additional malware (e.g., ransomware) across the managed network [1].
  • Business Risk: For internet-facing deployments, the business risk is catastrophic. Because N-central provides centralized management for multiple organizations, a compromise can lead to simultaneous ransomware deployment across all of an MSP’s downstream client environments, creating a massive supply chain security failure.

Sources

  1. CVE-2026-86218: Active Exploitation of N-able N-central

    This flaw allows unauthenticated attackers to execute arbitrary code on the N-central server before authentication enabling remote takeover of ...

  2. N-able N-central Pre-Auth RCE Flaw Exploited in the Wild

    CISA added actively exploited N-able N-central CVE-2026-86218 to KEV, with federal agencies ordered to patch by September 11.

  3. N-central 2026.3 Hotfix 4 – CVE-2026-86218 | N-able Status

    Build Number: 2026.3.1.14 Last Updated: Sept 5th 2026 Security Update This hotfix includes security fixes for CVE-2026-86218 which is a critical-CVSS-rated vulnerability that could allow for pre-authenticated remote code execution on the N-central server This vulnerability was responsibly disclosed…

  4. CVE Record: CVE-2026-86218

    N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14. CWE 1 Total. Learn more.