Full Report
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 11, 2026. The vulnerability in question is CVE-2026-86218 (CVSS score: 10.0), which has been described as a
Analysis Summary
# Vulnerability: N-able N-central Pre-Auth Remote Code Execution
## CVE Details
- **CVE ID**: CVE-2026-86218
- **CVSS Score**: 10.0 (Critical)
- **CWE**: CWE-94 (Static Code Injection)
## Affected Systems
- **Products**: N-able N-central (Remote Monitoring and Management platform)
- **Versions**: All versions prior to N-central 2026.3 Hotfix 4
- **Configurations**: Default configurations are likely vulnerable; specific conditions for exploitation include exposure of the management interface to the network.
## Vulnerability Description
CVE-2026-86218 is a maximum-severity static code injection vulnerability. The flaw resides in the way N-central handles input, allowing a remote, unauthenticated attacker to inject malicious code into the application. Because the injection occurs in a pre-authentication context, an attacker can achieve Remote Code Execution (RCE) without possessing valid credentials, potentially leading to a full compromise of the N-central appliance.
## Exploitation
- **Status**: Exploited in the wild. Added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on September 8, 2026.
- **Complexity**: Low
- **Attack Vector**: Network
## Impact
- **Confidentiality**: Total (Attackers can access all data managed by the RMM)
- **Integrity**: Total (Attackers can modify system settings or deploy malware to managed endpoints)
- **Availability**: Total (Attackers can disrupt service or lock out legitimate administrators)
## Remediation
### Patches
- **N-central 2026.3 Hotfix 4**: Released September 5, 2026. This is the primary fix for CVE-2026-86218.
- **N-central 2026.3 Hotfix 3**: Addresses related vulnerabilities CVE-2026-86206 and CVE-2026-86207 (Auth Bypass chain).
### Workarounds
- No specific software workarounds were provided. Administrators are urged to restrict network access to the N-central administration interface to trusted IP addresses only until the patch is applied.
## Detection
- **Indicators of Compromise**:
- Creation of unauthorized "System Administrator" accounts.
- Presence of suspicious files or modified scripts within the N-central directory.
- Unusual outbound network traffic from the N-central appliance.
- **Detection methods and tools**:
- Review N-central access logs (though logging may be limited on the appliance itself).
- CISA FCEB agencies are required to remediate by September 11, 2026.
## References
- **N-able Advisory**: hxxps[://]documentation[.]n-able[.]com/N-central/Release_Notes/GA/Content/N-central_2026.3_HF3_Release_Notes[.]htm
- **CISA KEV Catalog**: hxxps[://]www[.]cisa[.]gov/known-exploited-vulnerabilities-catalog
- **Rapid7 Technical Analysis**: hxxps[://]www[.]rapid7[.]com/blog/post/ve-cve-2026-86206-cve-2026-86207-n-able-n-central-authentication-bypass-fixed/
- **Huntress Investigation**: hxxps[://]www[.]huntress[.]com/blog/n-able-vulnerability-exploitation