N-able N-central Pre-Auth RCE Flaw Exploited in the Wild

Summary

CISA has added a critical vulnerability in N-able N-central, designated CVE-2026-86218, to its Known Exploited Vulnerabilities catalog. The flaw has a maximum severity score of 10.0 and is already being exploited in the wild. Federal agencies are required to patch this vulnerability by September 11, 2026.

IFF Assessment

FOE

The article details a critical vulnerability being actively exploited, posing a significant risk to organizations and requiring urgent patching.

Severity

9.8 Critical

CISA KEV: Listed as actively exploited. Federal patch due: September 11, 2026. Known ransomware use: Unknown.

Defender Context

This alert highlights a critical, actively exploited vulnerability in a widely used IT management platform. Defenders must prioritize patching CVE-2026-86218 in N-able N-central deployments to mitigate the risk of unauthorized access and further compromise.

Read Full Story →