CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

N-able N-central Pre-Auth RCE Flaw Exploited in the Wild

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6789

As cited

Copy frozen at (site build).

vulnerabilities

N-able N-central Pre-Auth RCE Flaw Exploited in the Wild

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-86218, a maximum-severity pre-authentication remote code execution (RCE) flaw in N-able N-central, to its Known Exploited Vulnerabilities (KEV) catalog on September 9, 2026. Federal Civilian Executive Branch agencies must remediate the vulnerability by September 11, 2026. The flaw carries a CVSS score of 10.0 and is being exploited in the wild.

Why it matters: Federal agencies and N-able N-central users face immediate exposure to unauthenticated RCE and must apply patches by the September 11 deadline; non-federal organizations running the software should prioritize remediation given active exploitation.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

N-able N-central Pre-Auth RCE Flaw Exploited in the Wild

CISA added CVE-2026-86218, a maximum-severity remote code execution flaw in N-able N-central, to its Known Exploited Vulnerabilities catalog on September 9, 2026. The vulnerability carries a CVSS score of 10.0 and is being actively exploited. Federal Civilian Executive Branch agencies must remediate the flaw by September 11, 2026.

Why it matters: N-able N-central administrators and FCEB agencies need to patch immediately, as this unauthenticated remote code execution vulnerability is confirmed in active exploitation and subject to federal compliance deadlines.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary