CVE-2026-86218: N-able N-central Static Code Injection Vulnerability

Summary

N-able N-central has a static code injection vulnerability that allows for remote code execution before authentication. Users must apply vendor mitigations and follow CISA guidance for patching.

IFF Assessment

FOE

A static code injection vulnerability enabling pre-authentication remote code execution poses a significant threat to defenders by allowing unauthorized access and control.

Severity

9.8 Critical

CISA KEV: Listed as actively exploited. Federal patch due: September 11, 2026. Known ransomware use: Unknown.

Defender Context

This vulnerability allows attackers to execute code remotely without authentication, posing a critical risk to organizations using N-able N-central. Defenders must prioritize applying vendor-provided mitigations and adhere to CISA's guidance on risk-based security updates to prevent potential exploitation.

Read Full Story →