CISA KEV: N-able N-central Static Code Injection Flaw (CVE-2026-86218) Actively Exploited
CISA has added CVE-2026-86218, a static code injection vulnerability in N-able N-central, to its Known Exploited Vulnerabilities (KEV) catalog, per N-able's advisory published September 6, 2026. N-able describes the flaw as capable of pre-authentication remote code execution.
What happened
N-able disclosed the vulnerability alongside a hotfix (N-central 2026.3 Hotfix 4). Its inclusion in the KEV catalog indicates CISA has evidence of active exploitation in the wild, though N-able's own advisory and the available reporting do not yet detail attacker TTPs, victim scope, or attribution. No CVSS score has been published for this CVE at the time of writing, and there is no confirmed link to ransomware activity.
Why it matters
N-central is a widely used remote monitoring and management (RMM) platform for managed service providers (MSPs), meaning a pre-auth RCE here carries outsized downstream risk: compromise of an N-central instance can potentially cascade to every endpoint the MSP manages on behalf of its customers. Static code injection vulnerabilities of this class are also attractive to attackers because they often require no valid credentials to exploit.
What defenders should do now
- Identify any N-central instances in your environment or your MSP's environment and confirm whether 2026.3 Hotfix 4 (or later) has been applied.
- Restrict N-central web interfaces to trusted networks/VPN where possible, and review external exposure of management consoles generally.
- Review N-central logs for anomalous authentication-less requests, unexpected process spawns from the N-central service account, or newly created scheduled tasks/scripts pushed through the RMM console.
- If you are an MSP customer, ask your provider directly whether they run N-central and whether the hotfix has been deployed.
- Treat any N-central server as a high-value target for lateral movement monitoring given its trust relationship with managed endpoints.
Developing situation
This is a same-day KEV addition and details are still emerging — patch guidance, exploitation specifics, and any related IOCs may be updated by N-able or CISA. For the authoritative advisory and hotfix instructions, see N-able's status page: https://status.n-able.com/2026/09/06/n-central-2026-3-hotfix-4-cve-2026-86218/.