CISA Adds Actively Exploited N-central RCE Flaw to KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-86218, a maximum-severity flaw in N-able N-central, to its Known Exploited Vulnerabilities catalog. The issue has a CVSS score of 10.0, is described as static code injection, and could permit pre-authentication remote code execution.
N-able said the vulnerability has been observed being exploited in the wild. The company patched it in N-central 2026.3 Hotfix 4, released on September 5, 2026, and urged customers to apply the update immediately.
Federal remediation deadline
CISA requires Federal Civilian Executive Branch agencies to apply the fixes by September 11, 2026. Its KEV entry states that the static code injection vulnerability in N-able N-central could allow an attacker to execute code remotely without first authenticating.
The catalog inclusion places the flaw among vulnerabilities for which CISA has evidence of exploitation. For organizations running N-central, the combination of a maximum severity rating, pre-authentication access and an active-exploitation notice makes the hotfix operationally urgent.
Compromise investigation leaves exploit path uncertain
Huntress began investigating after a customer’s fully patched N-central production environment was compromised on September 4. The incident occurred shortly before the release of Hotfix 4, but investigators said they could not determine definitively whether CVE-2026-86218 was the entry point.
Two other N-central vulnerabilities, CVE-2026-86206 and CVE-2026-86207, were patched on the same day in N-central 2026.3 Hotfix 3. Rapid7 researcher Stephen Fewer, who discovered and reported those issues, said they can be chained to let an unauthenticated remote attacker bypass authentication and create an attacker-controlled System Administrator account on an affected server.
Huntress said limited historical logging directly available on the appliance prevents it from confirming which exploit was used in the compromise or excluding the use of other vulnerabilities. That limitation is important when interpreting patch status: a system can be current at the time an investigation begins while an intrusion may have occurred before a relevant update was available or through another path.
What N-central operators should do
N-able said it is actively investigating the matter and has taken additional steps intended to help protect customer environments. Its direct customer notice calls for immediate deployment of N-central 2026.3 Hotfix 4.
Businesses using N-central should verify that Hotfix 4 is installed, check whether Hotfix 3 addressed the two related vulnerabilities in their environment, and preserve available logs and telemetry for review. Prompt patch validation and retained monitoring data are the practical priorities when a management platform faces an actively exploited pre-authentication RCE risk.

