CISA added CVE-2026-86218, a static code injection vulnerability enabling pre-authentication remote code execution in N-able's N-central remote monitoring and management platform, to its Known Exploited Vulnerabilities catalog on September 8, requiring Federal Civilian Executive Branch agencies to remediate by September 11. The flaw carries a maximum CVSS score of 10.0. N-able patched it in N-central 2026.3 Hotfix 4, released September 5, alongside two other vulnerabilities, CVE-2026-86206 and CVE-2026-86207, patched the same day via Hotfix 3. N-able issued an urgent notice stating the flaw "has been observed being exploited in the wild" and urged customers to patch immediately, saying it was continuing to investigate and had taken additional steps to protect customer environments. Security firm Huntress said it began its own investigation after finding a customer's fully patched N-central production environment had been compromised, with signs pointing to a compromise on September 4; Huntress said limited logging on the appliance meant it could not confirm which specific exploit the attacker used. Because N-central is used by managed service providers to administer client networks remotely, a compromise of the platform itself can expose every downstream client it manages, making this a supply-chain-style risk for MSP customers, including in India, that rely on N-central for remote IT administration.
US Cybersecurity and Data 12 Sept 2026
CISA Adds Maximum-Severity N-able N-central Flaw to Known Exploited Vulnerabilities Catalog
CISA added CVE-2026-86218, a maximum-severity (CVSS 10.0) pre-authentication remote code execution flaw in N-able's N-central remote monitoring platform, to its Known Exploited Vulnerabilities catalog on September 8, requiring federal agencies to remediate by September 11, after N-able confirmed active exploitation and researchers found a compromised customer environment.
Source: The Hacker News, September 9, 2026
Comments
0 commentsNo comments yet — be the first.