Key Facts
CISA added CVE-2026-86218 to its Known Exploited Vulnerabilities Catalog on September 8, 2026. CISA identifies the affected product as N-able N-central and describes a static code-injection vulnerability that could allow pre-authentication remote code execution.
Technical Details
N-able’s hotfix notice rates CVE-2026-86218 as Critical and says it could allow pre-authenticated remote code execution on an N-central server. The vendor says hosted N-central environments have already been patched.
Impact & Mitigation
CISA’s KEV entry directs organizations to apply vendor mitigations. For self-hosted deployments, N-able directs customers to upgrade to N-central 2026.3 Hotfix 4, build 2026.3.1.14, immediately. Review N-central exposure and follow the vendor’s upgrade guidance.
Sources
- CISA Known Exploited Vulnerabilities Catalog
- N-able N-central 2026.3 Hotfix 4 notice
- NVD: CVE-2026-86218
