CVE-2026-86207: N-able N-central

High severity, CVSS 7.7. EPSS: 1.3% chance of exploitation in the next 30 days.

An authentication bypass in N-central < 2026.3 HF 3 leads to authentication bypass in internal only APIs

Affected products

  • N-able N-central: before 2026.3.1.13 (fixed in 2026.3.1.13)

Published 2026-09-05. Last modified 2026-09-08.