CISA has added CVE-2026-86218, a critical static code injection flaw in N-able N-central, to its KEV catalog and ordered FCEB agencies to patch it by September 11, 2026. N-able said the issue has been exploited in the wild, while Huntress is investigating a compromise of a fully patched N-central environment and cannot confirm which vulnerability was used. #CVE-2026-86218 #N-able #N-central #Huntress #CISA
Keypoints
- CISA added CVE-2026-86218 to the KEV catalog.
- The flaw affects N-able N-central and allows pre-authentication remote code execution.
- N-able released N-central 2026.3 Hotfix 4 to fix the issue.
- N-able said CVE-2026-86218 has been exploited in the wild.
- Huntress is investigating a compromise and could not confirm the exact exploit used.
Read More: https://thehackernews.com/2026/09/n-able-n-central-pre-auth-rce-flaw.html