N-able N-Central Pre-Auth RCE Vulnerability CVE-2026-86218 Exploited in the Wild
A critical pre-authentication remote code execution (RCE) vulnerability (CVE-2026-86218) in N-able N-central has been actively exploited in the wild, prompting CISA to mandate urgent patching for federal agencies. The flaw, rated 10.0/10 on CVSS, allows attackers to compromise managed systems and propagate across connected networks, with ransomware groups specifically targeted due to the platform's strategic value.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 11, 2026.
The vulnerability in question is CVE-2026-86218 (CVSS score: 10.0), which has been described as a
*** END OF TRANSMISSION ***