BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

CISA adds N-able N-central static code injection flaw to KEV

CISA adds N-able N-central critical flaw to exploited catalog; urgent patching required for pre-auth RCE.

  • CISA added CVE-2026-86218, a maximum-severity static code injection vulnerability in N-able N-central, to its Known Exploited Vulnerabilities catalog.
  • The flaw, rated CVSS 10.0, allows pre-authentication remote code execution and has been patched in N-central 2026.3 Hotfix 4 released September 5, 2026.
  • Huntress is investigating a compromise of a fully patched N-central environment, while watchTowr confirmed exploitation of the vulnerability.
  • N-able issued an urgent notice stating the vulnerability is being exploited in the wild and urged immediate patching.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a maximum-severity security flaw in N-able N-central to its Known Exploited Vulnerabilities catalog on Tuesday, requiring federal agencies to apply fixes by September 11, 2026. The vulnerability, CVE-2026-86218, is a static code injection flaw with a CVSS score of 10.0 that enables pre-authentication remote code execution.

- Advertisement -

N-able patched the issue in N-central 2026.3 Hotfix 4, released on September 5, 2026. However, Huntress said it began investigating after a customer’s fully patched N-central production environment was compromised on September 4, 2026.

It remains unclear if the intrusion involved CVE-2026-86218 or two other vulnerabilities (CVE-2026-86206 and CVE-2026-86207) patched the same day. Those flaws can be chained to allow an unauthenticated attacker to bypass authentication and create a new System Administrator account, according to Rapid7’s Stephen Fewer.

Huntress noted that limited historical logging prevents definitive confirmation of which exploit was used. N-able sent an urgent notice to customers stating that CVE-2026-86218 has been observed exploited in the wild and that it is actively investigating.

Preemptive exposure management firm watchTowr said it successfully reproduced the vulnerability, calling it strategically valuable to threat actors. “This is precisely why N-central is so strategically valuable to threat actors, especially ransomware gangs,” said Yordan Ganchev of watchTowr. “Organizations running internet-facing N-central instances should prioritize upgrading to a patched release. However, as is now quickly becoming the new normal, patching alone is not enough.”

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Microsoft stock crosses $500, analysts predict surge to $600

Microsoft stock crossed $500, opening Tuesday at $509.JP Morgan maintains a buy rating with...

Brandt: Bitcoin’s bear market may be over, new cycle begins.

Veteran trader Peter Brandt now believes Bitcoin’s bear market has already ended and a...

‘Crypto King’ Aiden Pleterski must self-defend at fraud trial

An Ontario judge denied Aiden Pleterski's request to delay his fraud and money laundering...

Saylor outlines Bitcoin-backed yield-bearing digital dollars via STRC

Michael Saylor says a Bitcoin-backed stablecoin could offer 7% yield with near-zero volatility.Strategy’s STRC...

BitMine nears 5% of Ether supply, could hit target by November

BitMine Immersion Technologies currently holds 6,001,302 ETH, representing 4.9% of total supply, and needs...

Must Read

12 Hosting Providers To Buy VPS With Bitcoin: An Expert Guide for 2026

You need a VPS. You want to pay with Bitcoin. Simple enough, right?Not quite. The market for crypto VPS = VPS hosting that accepts...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading