Exploited in the wild N-central rce N-able
N-able N-central Pre-Auth RCE Flaw Exploited in the Wild
CVE Tools coverage
CISA has added CVE-2026-86218 to its Known Exploited Vulnerabilities catalog, mandating that federal agencies patch N-able N-central by September 11, 2026. This maximum-severity flaw (CVSS 10.0) enables pre-authentication remote code execution via static code injection. The vendor released a fix in N-central 2026.3 Hotfix 4 on September 5, 2026, following reports of active exploitation and customer compromises investigated by Huntress.