Vulnerability
Published 2026-09-05
Verified 2026-09-19

N-able N-central pre-auth RCE (CVE-2026-86218) CVSS 10; HF4 2026.3.1.14; WA SOC 20260907002

N-able N-central 2026.3 Hotfix 4 (build 2026.3.1.14, status post 6 September 2026, notes last updated 5 September) fixes CVE-2026-86218, a critical pre-authenticated remote code execution flaw (static code injection) on the N-central server. WA SOC advisory 20260907002 (7 September 2026, TLP:CLEAR) rates it CVSS 10 Critical for N-central prior to 2026.3.1.14 and points to N-able security advisory aArVy0000002Ld3KAE. Hosted NCOD instances are already patched; on-premises customers must upgrade to HF4 immediately (HF3 / 2026.3.1.13 remains vulnerable to this CVE). The preceding Hotfix 3 (5 September) fixed high-severity authentication-bypass CVE-2026-86206 and CVE-2026-86207. NEW 8–9 Sep: CISA added CVE-2026-86218 to the KEV catalog on 2026-09-08 (catalog 2026.09.08) as static code injection / pre-auth RCE; FCEB dueDate 2026-09-11; forensicTriage Yes; KEV notes link the N-able status post and advisory aArVy0000002Ld3KAE. The Hacker News (9 Sep 2026) reports Huntress investigating compromise of a customer's fully patched N-central on 2026-09-04 (unclear whether CVE-2026-86218 or the HF3 pair CVE-2026-86206/86207); a separate N-able urgent customer notice says CVE-2026-86218 has been observed exploited in the wild. Shadowserver has tracked roughly 1,500 internet-exposed N-central servers. Distinct from desk card n-able-n-central-2026 (August CVE-2026-18556 / CVE-2026-18577 and ACSC AU exploitation). Primary: N-able status HF4; WA SOC 20260907002; CISA KEV / THN for exploitation update.

Product
N-able N-central (on-premises)
Versions
Prior to 2026.3.1.14 (HF4); HF3 2026.3.1.13 still vulnerable to CVE-2026-86218. Hosted NCOD already patched.
CVSS
10.0 (WASOC; vendor Critical)
Exploited in Australia?
unknown
Patch to
N-central 2026.3 Hotfix 4 (2026.3.1.14) immediately for on-prem; hosted NCOD no action

Primary: N-able status — N-central 2026.3 HF4 / CVE-2026-86218 (6 Sep 2026) · Vendor: WA SOC 20260907002 (7 Sep 2026) · CVE: CVE-2026-86218, CVE-2026-86206, CVE-2026-86207, CVE-2026-18556, CVE-2026-18577 · The Hacker News — N-central pre-auth RCE / KEV (9 Sep 2026)

vulnerabilities australia cloud identity