CISA_KEV · SEPTEMBER 2026 · EARLY WARNING

N-able N-central Pre-Auth RCE Vulnerability: Early Warning

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
HIGH
Affected component
n-able n-central (other)
Patched version
Not yet available
CVE-2026-86218

N-able N-central reportedly contains a static code injection vulnerability that could allow for pre-authentication remote code execution. This issue is under investigation.

What happened

N-able N-central is under investigation for a static code injection vulnerability identified as CVE-2026-86218. This vulnerability could potentially allow pre-authentication remote code execution. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added this flaw to its Known Exploited Vulnerabilities catalog. N-able has released N-central 2026.3 Hotfix 4 on September 5, 2026, which includes a patch for this vulnerability. However, it remains unclear if the recent compromise of a customer's fully patched N-central environment involved CVE-2026-86218 or other vulnerabilities.

Huntress is investigating a compromise that occurred on September 4, 2026. The intrusion method is not definitively confirmed, and it is unclear which specific vulnerabilities were exploited. N-able has issued an urgent notice to customers, but the exact nature of the compromise is still under investigation.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If n-able n-central is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

If you are using N-able N-central, you may be affected. Consult the primary sources for the latest information.

What should I do right now?

Apply the N-central 2026.3 Hotfix 4 patch and monitor your environments for any signs of exploitation.

Has this been exploited in the wild?

Yes, CVE-2026-86218 has been reportedly exploited in the wild.

Sources

Join the 0Day waitlist →

← Back to all threats