CVE-2026-86218
N-central Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-86218 is a pre-authentication remote code execution (RCE) vulnerability in N-able N-central, a widely used IT management and monitoring platform. It affects all versions of N-central before 2026.3.1.14 and was published on September 6, 2026. The vulnerability carries a CVSS v4.0 base score of 10.0 (Critical), reflecting its network-exploitable, zero-authentication, zero-interaction nature (GitHub Advisory, N-able Status).

Détails techniques

The vulnerability is classified as CWE-96 (Improper Neutralization of Directives in Statically Saved Code / Static Code Injection), meaning the application fails to properly sanitize attacker-supplied input before embedding it into an executable resource such as a configuration file, library, or template (GitHub Advisory). Feedly's analysis also estimates a secondary classification of CWE-502 (Deserialization of Untrusted Data) as a contributing factor. The attack vector is fully remote (network-accessible), requires no privileges, no user interaction, and no special attack conditions, making it trivially automatable against any exposed N-central instance running a vulnerable version.

Impact

Successful exploitation allows an unauthenticated remote attacker to execute arbitrary code on the N-central server with the privileges of the running service. Given N-central's role as a centralized IT management platform managing endpoints, credentials, and network devices across customer environments, a compromise could result in full confidentiality, integrity, and availability loss on both the vulnerable system and all subsequently managed systems (GitHub Advisory, N-able Advisory). The potential for lateral movement into managed endpoints and downstream customer infrastructure is extremely high, making this a critical supply-chain-level risk for managed service providers (MSPs).

Exploitabilité

As of the time of publication, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation (GitHub Advisory). The EPSS score is currently 0.0, reflecting the early stage of public awareness. The vulnerability has not yet been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. However, given the critical severity, zero-authentication requirement, and the high-value nature of N-central deployments in MSP environments, the risk of rapid weaponization is significant.

Atténuation et solutions de contournement

N-able has released a patch in N-central version 2026.3.1.14 (Hotfix 4), and all users should upgrade immediately (N-able Status, N-able Advisory). As an interim measure, organizations should implement network segmentation and strict access controls to restrict N-central's management interface to trusted internal networks or VPN-only access. Monitoring for anomalous network activity targeting N-central endpoints is also recommended until patching is complete.

Réactions de la communauté

The vulnerability was noted on Mastodon shortly after disclosure, and multiple vulnerability tracking platforms (VulnDB, CVEFeed, CIRCL, ENISA EUVD) indexed it rapidly following publication (N-able Status). N-able published an official security advisory and a status page entry acknowledging the issue and directing users to the hotfix. No significant independent researcher commentary or broader media coverage has been identified at this time.

Ressources additionnelles


SourceCe rapport a été généré à l’aide de l’IA

Apparenté N-central Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-86218CRITICAL10
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
NonOuiSep 06, 2026
CVE-2026-18577HIGH8.2
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
OuiOuiAug 02, 2026
CVE-2026-18556HIGH8.2
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
OuiOuiAug 01, 2026
CVE-2026-86207HIGH7.7
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
NonOuiSep 05, 2026
CVE-2026-86206MEDIUM6.9
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
NonOuiSep 05, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités