CVE-2026-86218 is a critical (CVSS 10.0) pre-authentication remote code execution vulnerability in N-able N-central, an RMM platform widely used by MSPs. Unauthenticated remote attackers can achieve full code execution on the server over the network with no user interaction, and the flaw is confirmed to be actively exploited in the wild (CISA KEV listed). This is a textbook T1190 initial access vulnerability granting complete server takeover.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2026-09-06
Added to CISA KEV: 2026-09-08 2 DAYS BETWEEN CVE AND KEV
CVE-2026-86218 is a critical-severity, pre-authentication remote code execution (RCE) vulnerability affecting the N-able N-central server management platform. The flaw allows unauthenticated remote attackers to execute arbitrary code on an affected server, effectively granting them full administrative control over the system. This vulnerability is highly significant because N-central is frequently used by Managed Service Providers (MSPs) to manage the IT environments of numerous downstream customers, making it a high-value target that can serve as a conduit for wide-scale supply chain attacks.
This flaw allows unauthenticated attackers to execute arbitrary code on the N-central server before authentication enabling remote takeover of ...
CISA added actively exploited N-able N-central CVE-2026-86218 to KEV, with federal agencies ordered to patch by September 11.
Build Number: 2026.3.1.14 Last Updated: Sept 5th 2026 Security Update This hotfix includes security fixes for CVE-2026-86218 which is a critical-CVSS-rated vulnerability that could allow for pre-authenticated remote code execution on the N-central server This vulnerability was responsibly disclosedβ¦
N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14. CWE 1 Total. Learn more.