N-able N-central Pre-Auth RCE Flaw Exploited in the Wild
AI-summarised brief · reviewed before publication
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a maximum‑severity, CVSS 10.0 flaw in N‑able N‑central (CVE‑2026‑86218) to its Known Exploited Vulnerabilities catalog, mandating Federal Civilian Executive Branch agencies to install the September 5, 2026 hotfix by September 11, 2026. The vulnerability is a static‑code injection that enables pre‑authentication remote code execution. Huntress reported a compromise of a fully patched N‑central environment on September 4, 2026, but could not confirm whether the breach used CVE‑2026‑86218 or two other same‑day patches (CVE‑2026‑86206, CVE‑2026‑86207) that allow unauthenticated attackers to create admin accounts. N‑able confirmed the exploit is active in the wild and urged immediate remediation.
💡 Why It Matters
- · Exploitation of a flawless, pre‑auth RCE gives attackers unrestricted control over managed IT infrastructure, forcing rapid patch adoption across critical government networks.