N-able N-central Pre-Auth RCE Flaw Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 11, 2026.
The vulnerability in question is CVE-2026-86218 (CVSS score: 10.0), which has been described as a case of static code injection. It has been patched in N-central 2026.3 Hotfix 4, released on September 5, 2026.
“N-able N-central contains a static code injection vulnerability that could allow for pre-authentication remote code execution,” CISA said.
The development came shortly after Huntress said it commenced an investigation following the compromise of a customer’s fully patched N-central production environment on September 4, 2026.
However, it remains unclear if the intrusion involved CVE-2026-86218 or two other vulnerabilities (CVE-2026-86206 and CVE-2026-86207) that were patched by N-able the same day with N-central 2026.3 Hotfix 3. CVE-2026-86206 and CVE-2026-86207 can be chained together to allow a remote unauthenticated attacker to bypass authentication and create a new attacker-controlled System Administrator account on an affected server, per Rapid7’s Stephen Fewer, who discovered and reported them.
“Due to limited historical logging available directly on the appliance, we cannot definitively confirm which specific exploit the threat actor used to achieve their compromise, nor can we rule out the use of alternative vulnerabilities,” Huntress noted.
In a separate “urgent” notice sent directly to customers, N-able said CVE-2026-86218 “has been observed being exploited in the wild” and that it’s “actively investigating this matter and have taken additional steps to help protect customer environments.” It also urged customers to apply the hotfix immediately.
The post “N-able N-central Pre-Auth RCE Flaw Exploited in the Wild” appeared first on The Hacker News
Source:The Hacker News – [email protected] (The Hacker News)
