thehackernews.com 9 Sept 2026, 04:27 UTC

CISA Warns Attackers Are Exploiting N-able N-central Flaw

CyberSIXT Evidence Panel

CISA added a high-severity vulnerability in N-able N-central to its Known Exploited Vulnerabilities catalog, with CVE-2026-86218 described as a static code injection that could permit pre-authentication remote code execution. The flaw has been patched in N-central 2026.3 Hotfix 4, released on 5 September 2026. Public reporting indicates the issue has been observed being exploited in the wild, and N-able urged customers to apply the hotfix promptly. The KEV listing underscores the urgency for affected agencies to address the flaw by 11 September 2026.

There is a live discussion about whether CVE-2026-86218 was the exact vector used in the reported compromise, or whether attackers relied on one or more of the related issues patched the same day—CVE-2026-86206 and CVE-2026-86207—which can be chained to bypass authentication and create an attacker-controlled System Administrator account. Huntress noted that limited historical logging on the appliance makes definitive attribution difficult and did not rule out other vulnerabilities.

N-able’s separate urgent notice reiterated that CVE-2026-86218 has been observed being exploited and confirmed that the company is investigating while offering protections and a direct recommendation to apply the hotfix.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline