"N-able N-central contains a static code injection vulnerability that could allow for pre-authentication remote code execution," CISA said.
CISA adds CVE-2026-86218 to KEV and sets a federal deadline
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added CVE-2026-86218 — a maximum-severity flaw with a CVSS score of 10.0 — to its Known Exploited Vulnerabilities (KEV) catalog. The listing requires Federal Civilian Executive Branch (FCEB) agencies to apply fixes by September 11, 2026. CISA described the issue as a case of static code injection and tied it explicitly to pre-authentication remote code execution.
Patch timeline: Hotfix 3 and Hotfix 4, both released September 5, 2026
N-able issued patches on September 5, 2026. CVE-2026-86218 was patched in N-central 2026.3 Hotfix 4. Two additional defects — CVE-2026-86206 and CVE-2026-86207 — were patched by N-able the same day in N-central 2026.3 Hotfix 3. Customers were urged to apply the hotfixes immediately.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleHuntress investigation following a September 4 compromise
Security firm Huntress said it commenced an investigation after a customer's fully patched N-central production environment was compromised on September 4, 2026. Huntress reported that, "Due to limited historical logging available directly on the appliance, we cannot definitively confirm which specific exploit the threat actor used to achieve their compromise, nor can we rule out the use of alternative vulnerabilities."
Rapid7 discovery: CVE-2026-86206 and CVE-2026-86207 can be chained
Rapid7 researcher Stephen Fewer discovered and reported CVE-2026-86206 and CVE-2026-86207. According to Fewer, those two vulnerabilities can be chained to allow a remote unauthenticated attacker to bypass authentication and create a new attacker-controlled System Administrator account on an affected server. It remains unclear whether the intrusion Huntress is investigating involved CVE-2026-86218 or the pair of chainable vulnerabilities patched in Hotfix 3.
How FCEB agencies, N-able customers, and incident responders are positioned
- FCEB agencies: Subject to CISA's KEV action, agencies are required to apply the fixes by September 11, 2026, making the next 48–72 hours a hard compliance window for the affected N-central versions.
- N-able customers (administrators and operators): N-able sent an "urgent" notice directly to customers stating CVE-2026-86218 "has been observed being exploited in the wild," that it is "actively investigating this matter and have taken additional steps to help protect customer environments," and urging immediate application of the hotfixes released September 5.
- Incident responders and researchers: Huntress' note about limited historical logging on the appliance highlights a practical constraint on attribution and post-compromise forensics; responders will need to work with available telemetry and vendor-provided mitigation steps while N-able continues its investigation.
The near-term facts are plain: N-able published two hotfixes on September 5, 2026, CISA placed CVE-2026-86218 on the KEV list with a September 11 remediation deadline for FCEB agencies, Huntress is investigating a September 4 compromise of a fully patched N-central environment, and Rapid7's Stephen Fewer reported two chainable vulnerabilities that permit unauthenticated privilege escalation. N-able has told customers that CVE-2026-86218 "has been observed being exploited in the wild" and has urged immediate patching while it continues to investigate.
What remains to be resolved in the days ahead is whether forensic analysis or vendor telemetry will identify which vulnerability or combination of vulnerabilities was exploited in the September 4 incident, and whether additional compromises will emerge as investigators and administrators apply the hotfixes required by CISA.
Original reporting: https://thehackernews.com/2026/09/n-able-n-central-pre-auth-rce-flaw.html




