Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2026-86218: N-able N-central allows remote code execution before login
CVE-2026-86218 · published 23 days ago · actively exploited
Summary
The N-able N-central management system can be tricked into running malicious code without any user authentication. This means an attacker could take control of the server that runs N-central from anywhere on the network. Apply the vendor’s security update or patch as soon as possible to close the gap.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| n-able | n-central |
< 2026.3.1.14 < 2026.3 2026.3 |
Original advisory text
N-able N-central Static Code Injection Vulnerability
N-able N-central contains a static code injection vulnerability that could allow for pre-authentication remote code execution.
References
Severity
10.0
Critical
Exploitation
Known exploited
Listed in the CISA KEV catalogue - exploitation confirmed in the wild.
EPSS 13%
Type
CWE-96Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')
Timeline
Published6 Sep 2026
Updated29 Sep 2026
First seen6 Sep 2026
Track software like this
Free during beta