
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-86218 is a pre-authentication remote code execution (RCE) vulnerability in N-able N-central, a widely deployed remote monitoring and management (RMM) platform used by managed service providers (MSPs). The flaw is classified as Static Code Injection (CWE-96) and allows unauthenticated network attackers to execute arbitrary code without any user interaction. All N-central versions before 2026.3.1.14 are affected, including 2026.3, 2026.3-hotfix1, 2026.3-hotfix2, and 2026.3-hotfix3. The vulnerability was published on September 6, 2026, and carries a CVSS v3.1 base score of 9.8 (Critical) and a CVSS v4.0 base score of 10.0 (Critical) (GitHub Advisory, CISA KEV).
The root cause is improper neutralization of directives in statically saved code (CWE-96 — Static Code Injection), meaning attacker-controlled input is written into an executable resource (such as a configuration file, library, or template) without adequate sanitization, enabling code execution upon subsequent processing. The attack vector is fully network-accessible, requires no privileges, no user interaction, and no special attack conditions, making it trivially automatable. Feedly's estimate also flags CWE-502 (Deserialization of Untrusted Data) as a potential contributing weakness. The vulnerability is part of a broader chain of N-central flaws (alongside CVE-2026-86206 and CVE-2026-86207) that were disclosed in the same period, representing the third major attack wave against N-central in approximately six weeks (GitHub Advisory, CTI Pilot, Horizon3).
Successful exploitation grants an unauthenticated remote attacker full code execution on the N-central server with high impact to confidentiality, integrity, and availability of both the vulnerable system and subsequent systems it manages. Because N-central is an RMM platform with privileged access to thousands of managed endpoints across MSP customer environments, compromise of a single N-central instance can enable mass lateral movement, ransomware deployment, and data exfiltration across all managed organizations. Approximately 1,500 internet-exposed N-central servers were identified as potentially vulnerable at the time of disclosure (Rescana, Undercode Testing).
CVE-2026-86218 is confirmed as actively exploited in the wild and was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on September 8, 2026, with a remediation due date of September 11, 2026 (CISA KEV). The NVD SSVC assessment classifies exploitation as "active," technical impact as "total," and the vulnerability as "automatable." A GitHub repository claiming to be a PoC (HORKimhab/CVE-2026-86218) was published on September 7, 2026, but analysis determined it contains no actual exploit code. A Metasploit module pull request was submitted (rapid7/metasploit-framework#21896), and Nuclei detection templates were also developed and merged. The EPSS score is approximately 0.41% per Feedly data, though the GitHub Advisory Database reports a 7.494% EPSS (94th percentile), indicating elevated exploitation probability. The vulnerability is noted as potentially used in ransomware campaigns per CISA's KEV entry (CISA KEV, GitHub Advisory).
bash, sh, cmd.exe, powershell, curl, wget); unexpected network connections initiated by the N-central process.N-able released N-central version 2026.3 Hotfix 4 (build 2026.3.1.14) to address this vulnerability; all organizations should upgrade immediately (N-able Status, N-able Advisory). CISA mandated federal agencies apply mitigations by September 11, 2026, and also requires forensic triage per BOD 26-04 for affected systems (CISA KEV). As a temporary workaround where immediate patching is not possible, restrict network access to N-central management interfaces using firewall rules or VPN, limiting exposure to trusted IP ranges only. Organizations should also audit N-central for signs of compromise before applying the patch, given active exploitation in the wild.
The vulnerability generated significant industry attention, described by multiple outlets as a "god mode" flaw due to its CVSS 10.0 score and the privileged position N-central holds in MSP environments (Help Net Security, The Hacker News). Security researchers noted this was the fourth hotfix N-able issued in five weeks, with CSO Online characterizing the situation as "back-to-back N-able bugs send admins on a patching spree" (CSO Online). Huntress, Arctic Wolf, eSentire, and Horizon3.ai all published dedicated advisories or blog posts, with Horizon3 providing attack research details (Huntress, Arctic Wolf, eSentire, Horizon3). Community commentary on Reddit and Mastodon highlighted the MSP supply-chain risk, with one blogger framing the repeated N-central exploits as "an MSP vendor risk test" (Reddit).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."