CISA KEV Alert 8 Sept 2026, 21:01 UTC

Attackers Exploit Critical N-able N-central Flaw Before Authentication

CyberSIXT Evidence Panel Source marked as original reporting
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Status Unknown

CISA added CVE-2026-86218 to its Known Exploited Vulnerabilities (KEV) catalogue on 8 September 2026. The vulnerability affects N-able N-central and is known as the N-able N-central Static Code Injection Vulnerability. It could allow unauthenticated attackers to execute code remotely before authentication.

The flaw is a static code injection vulnerability with a pre-authentication remote code execution impact. The available data does not specify the attack vector beyond its pre-authentication nature. NVD rates the vulnerability CVSS 10.0, Critical. Patch availability is currently unknown, although N-able has published vendor advisory information concerning the issue.

CISA’s KEV listing confirms that attackers are actively exploiting the vulnerability. The available data does not confirm use in ransomware campaigns. Federal Civilian Executive Branch (FCEB) agencies must complete remediation by 11 September 2026.

CISA requires agencies to “apply mitigations in accordance with vendor instructions”, while ensuring compliance with BOD 26-04, Prioritising Security Updates Based on Risk, and CISA’s Forensics Triage Requirements. Agencies must follow applicable BOD 26-04 guidance for cloud services or discontinue use of N-central if mitigations are unavailable. Stakeholders must assess each asset’s internet exposure and follow BOD 26-04 patching guidance. Although the deadline applies directly to FCEB agencies, all organisations should review their exposure and apply relevant mitigations.

See the linked NVD entry and CISA KEV catalogue for full details.

View CISA KEV Entry

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline