Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-86218: N-able N-central allows remote code execution before login

CVE-2026-86218 · published 23 days ago · actively exploited
Summary

The N-able N-central management system can be tricked into running malicious code without any user authentication. This means an attacker could take control of the server that runs N-central from anywhere on the network. Apply the vendor’s security update or patch as soon as possible to close the gap.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
n-able n-central < 2026.3.1.14
< 2026.3
2026.3
Original advisory text
N-able N-central Static Code Injection Vulnerability
N-able N-central contains a static code injection vulnerability that could allow for pre-authentication remote code execution.
Severity
10.0 Critical
Exploitation
Known exploited
Listed in the CISA KEV catalogue - exploitation confirmed in the wild.
EPSS 13%
Type
CWE-96Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')
Timeline
Published6 Sep 2026
Updated29 Sep 2026
First seen6 Sep 2026
Sources
CVE-2026-86218 · MITRE
CVE-2026-86218 · CISA KEV
Track software like this
Free during beta