- CISA added CVE-2026-86218, a maximum-severity static code injection vulnerability in N-able N-central, to its Known Exploited Vulnerabilities catalog.
- The flaw, rated CVSS 10.0, allows pre-authentication remote code execution and has been patched in N-central 2026.3 Hotfix 4 released September 5, 2026.
- Huntress is investigating a compromise of a fully patched N-central environment, while watchTowr confirmed exploitation of the vulnerability.
- N-able issued an urgent notice stating the vulnerability is being exploited in the wild and urged immediate patching.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a maximum-severity security flaw in N-able N-central to its Known Exploited Vulnerabilities catalog on Tuesday, requiring federal agencies to apply fixes by September 11, 2026. The vulnerability, CVE-2026-86218, is a static code injection flaw with a CVSS score of 10.0 that enables pre-authentication remote code execution.
N-able patched the issue in N-central 2026.3 Hotfix 4, released on September 5, 2026. However, Huntress said it began investigating after a customer’s fully patched N-central production environment was compromised on September 4, 2026.
It remains unclear if the intrusion involved CVE-2026-86218 or two other vulnerabilities (CVE-2026-86206 and CVE-2026-86207) patched the same day. Those flaws can be chained to allow an unauthenticated attacker to bypass authentication and create a new System Administrator account, according to Rapid7’s Stephen Fewer.
Huntress noted that limited historical logging prevents definitive confirmation of which exploit was used. N-able sent an urgent notice to customers stating that CVE-2026-86218 has been observed exploited in the wild and that it is actively investigating.
Preemptive exposure management firm watchTowr said it successfully reproduced the vulnerability, calling it strategically valuable to threat actors. “This is precisely why N-central is so strategically valuable to threat actors, especially ransomware gangs,” said Yordan Ganchev of watchTowr. “Organizations running internet-facing N-central instances should prioritize upgrading to a patched release. However, as is now quickly becoming the new normal, patching alone is not enough.”
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
Previous Articles:
- Russia Pushes BRICS to Settle 90% Trade in Local Currencies
- 1Gbits vs OVH vs Hetzner: Which Bare Metal Provider Wins on Price and Performance
- Pitch Fest Bali 2026 Wraps: ObsessionDB Wins, 13 Startups Pitch to a Room of Leading VCs
- Chanos vs Nvidia: Can GPU Renters Sustain Returns?
- Singaporean pleads guilty in $245M crypto RICO case
