CISA added a high-severity vulnerability in N-able N-central to its Known Exploited Vulnerabilities catalog, with CVE-2026-86218 described as a static code injection that could permit pre-authentication remote code execution. The flaw has been patched in N-central 2026.3 Hotfix 4, released on 5 September 2026. Public reporting indicates the issue has been observed being exploited in the wild, and N-able urged customers to apply the hotfix promptly. The KEV listing underscores the urgency for affected agencies to address the flaw by 11 September 2026.
There is a live discussion about whether CVE-2026-86218 was the exact vector used in the reported compromise, or whether attackers relied on one or more of the related issues patched the same day—CVE-2026-86206 and CVE-2026-86207—which can be chained to bypass authentication and create an attacker-controlled System Administrator account. Huntress noted that limited historical logging on the appliance makes definitive attribution difficult and did not rule out other vulnerabilities.
N-able’s separate urgent notice reiterated that CVE-2026-86218 has been observed being exploited and confirmed that the company is investigating while offering protections and a direct recommendation to apply the hotfix.