As cited
Copy frozen at (site build).
vulnerabilities
N-able N-central Pre-Auth RCE Flaw Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-86218, a maximum-severity pre-authentication remote code execution (RCE) flaw in N-able N-central, to its Known Exploited Vulnerabilities (KEV) catalog on September 9, 2026. Federal Civilian Executive Branch agencies must remediate the vulnerability by September 11, 2026. The flaw carries a CVSS score of 10.0 and is being exploited in the wild.
Why it matters: Federal agencies and N-able N-central users face immediate exposure to unauthenticated RCE and must apply patches by the September 11 deadline; non-federal organizations running the software should prioritize remediation given active exploitation.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
N-able N-central Pre-Auth RCE Flaw Exploited in the Wild
CISA added CVE-2026-86218, a maximum-severity remote code execution flaw in N-able N-central, to its Known Exploited Vulnerabilities catalog on September 9, 2026. The vulnerability carries a CVSS score of 10.0 and is being actively exploited. Federal Civilian Executive Branch agencies must remediate the flaw by September 11, 2026.
Why it matters: N-able N-central administrators and FCEB agencies need to patch immediately, as this unauthenticated remote code execution vulnerability is confirmed in active exploitation and subject to federal compliance deadlines.
- Source published
- First seen by Cybersecurity Tracker