
PEACH
Un cadre d’isolation des locataires
CVE-2026-86218 is a pre-authentication remote code execution (RCE) vulnerability in N-able N-central, a widely used IT management and monitoring platform. It affects all versions of N-central before 2026.3.1.14 and was published on September 6, 2026. The vulnerability carries a CVSS v4.0 base score of 10.0 (Critical), reflecting its network-exploitable, zero-authentication, zero-interaction nature (GitHub Advisory, N-able Status).
The vulnerability is classified as CWE-96 (Improper Neutralization of Directives in Statically Saved Code / Static Code Injection), meaning the application fails to properly sanitize attacker-supplied input before embedding it into an executable resource such as a configuration file, library, or template (GitHub Advisory). Feedly's analysis also estimates a secondary classification of CWE-502 (Deserialization of Untrusted Data) as a contributing factor. The attack vector is fully remote (network-accessible), requires no privileges, no user interaction, and no special attack conditions, making it trivially automatable against any exposed N-central instance running a vulnerable version.
Successful exploitation allows an unauthenticated remote attacker to execute arbitrary code on the N-central server with the privileges of the running service. Given N-central's role as a centralized IT management platform managing endpoints, credentials, and network devices across customer environments, a compromise could result in full confidentiality, integrity, and availability loss on both the vulnerable system and all subsequently managed systems (GitHub Advisory, N-able Advisory). The potential for lateral movement into managed endpoints and downstream customer infrastructure is extremely high, making this a critical supply-chain-level risk for managed service providers (MSPs).
As of the time of publication, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation (GitHub Advisory). The EPSS score is currently 0.0, reflecting the early stage of public awareness. The vulnerability has not yet been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. However, given the critical severity, zero-authentication requirement, and the high-value nature of N-central deployments in MSP environments, the risk of rapid weaponization is significant.
N-able has released a patch in N-central version 2026.3.1.14 (Hotfix 4), and all users should upgrade immediately (N-able Status, N-able Advisory). As an interim measure, organizations should implement network segmentation and strict access controls to restrict N-central's management interface to trusted internal networks or VPN-only access. Monitoring for anomalous network activity targeting N-central endpoints is also recommended until patching is complete.
The vulnerability was noted on Mastodon shortly after disclosure, and multiple vulnerability tracking platforms (VulnDB, CVEFeed, CIRCL, ENISA EUVD) indexed it rapidly following publication (N-able Status). N-able published an official security advisory and a status page entry acknowledging the issue and directing users to the hotfix. No significant independent researcher commentary or broader media coverage has been identified at this time.
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."