CVE-2026-86218: N-able N-central Static Code Injection Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2026-09-08. EPSS: 14.5% chance of exploitation in the next 30 days.
N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.
Affected products
- N-able N-central: before 2026.3 (fixed in 2026.3); version 2026.3 only
Published 2026-09-06. Last modified 2026-09-09.