๐ฅ This vulnerability is being actively exploited in the wild (CISA Known Exploited Vulnerabilities catalog)
CVE-2026-86218: N-able N-central Static Code Injection Vulnerability
Summary
N-able N-central has a static code injection vulnerability (a flaw where attackers can insert harmful code into the software) that allows attackers to execute code remotely before even logging in. This is a serious issue that is currently being exploited by attackers in real-world attacks.
Solution / Mitigation
Apply mitigations according to vendor instructions, following CISA's BOD 26-04 guidance on prioritizing security updates. N-able released N-central 2026.3 hotfix 4 to address CVE-2026-86218 (see https://status.n-able.com/2026/09/06/n-central-2026-3-hotfix-4-cve-2026-86218/). If mitigations are unavailable, discontinue use of the product. The patching deadline is 2026-09-11.
Vulnerability Details
EPSS: 0.4%
Yes
๐ฅ Actively Exploited
September 7, 2026
Classification
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-86218
First tracked: September 8, 2026 at 08:01 PM
Classified by LLM (prompt v3) ยท confidence: 95%