N-able N-central Pre-Auth RCE Flaw Exploited in the Wild

N-able N-central Pre-Auth RCE Flaw Exploited in the Wild
CISA has added CVE-2026-86218, a critical static code injection flaw in N-able N-central, to its KEV catalog and ordered FCEB agencies to patch it by September 11, 2026. N-able said the issue has been exploited in the wild, while Huntress is investigating a compromise of a fully patched N-central environment and cannot confirm which vulnerability was used. #CVE-2026-86218 #N-able #N-central #Huntress #CISA

Keypoints

  • CISA added CVE-2026-86218 to the KEV catalog.
  • The flaw affects N-able N-central and allows pre-authentication remote code execution.
  • N-able released N-central 2026.3 Hotfix 4 to fix the issue.
  • N-able said CVE-2026-86218 has been exploited in the wild.
  • Huntress is investigating a compromise and could not confirm the exact exploit used.

Read More: https://thehackernews.com/2026/09/n-able-n-central-pre-auth-rce-flaw.html