← Back to blog

Critical N-able N-central RCE Flaw Actively Exploited

A pre-authentication remote code execution flaw in N-able N-central has been added to CISA's KEV catalog. Federal agencies must patch by September 11, 2026.

TL;DR

  • CVE-2026-86218 is a critical pre-auth RCE flaw in N-able N-central with a CVSS score of 10.0.
  • CISA added the vulnerability to its Known Exploited Vulnerabilities catalog.
  • FCEB agencies are required to apply patches by September 11, 2026.
  • The flaw is being actively exploited in the wild.
  • Organizations using N-able N-central should prioritize immediate remediation.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical remote code execution (RCE) vulnerability in N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog. Rated with a maximum CVSS score of 10.0, CVE-2026-86218 allows unauthenticated attackers to execute arbitrary code on affected systems.

This move by CISA underscores the severity and active exploitation of the flaw. Federal Civilian Executive Branch (FCEB) agencies have been directed to apply necessary updates by September 11, 2026. Organizations relying on N-able N-central for IT management should treat this as a high-priority security issue.

Vulnerability Details

  • CVE-2026-86218 is a pre-authentication remote code execution vulnerability in N-able N-central.
  • It carries a critical CVSS v3 score of 10.0, indicating the highest level of severity.
  • The flaw allows unauthenticated attackers to remotely execute arbitrary code on vulnerable systems.
  • No user interaction or additional privileges are required for exploitation.

Impact and Response

  • CISA has added the vulnerability to its KEV catalog, signaling known active exploitation.
  • Federal agencies must remediate the issue by September 11, 2026.
  • N-able has released patches to address the vulnerability; customers should update immediately.
  • Organizations outside the federal sector are also strongly advised to patch due to active exploitation.

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.

Critical N-able N-central RCE Flaw Actively Exploited — Agent Breach Blog | Agent Breach