CVE-2026-86218, a CVSS 9.8 static code injection vulnerability in N-able’s N-central remote monitoring and management (RMM) platform, was added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on September 8, 2026. NVD’s vector confirms the flaw is network-exploitable, requires no privileges and no user interaction, and carries high impact to confidentiality, integrity, and availability.
What the vulnerability does
NVD classifies CVE-2026-86218 under CWE-96 (Improper Neutralization of Directives in Statically Saved Code, i.e. static code injection). Per NVD’s description, N-central is vulnerable to pre-authentication remote code execution, affecting all N-central releases before version 2026.3.1.14. N-able’s own security advisory (linked from NVD’s reference data) names the issue directly as a pre-authentication RCE.
Why it’s on KEV
CISA’s September 8 KEV addition places CVE-2026-86218 under BOD 26-04’s remediation-by-deadline requirement for federal civilian agencies. N-able’s advisory is the primary vendor source; CISA’s KEV entry directs affected organizations to that guidance and to independently assess internet-facing exposure of any N-central instance.
What we don’t yet have
CVSS scoring, the vulnerability description, and the affected-version data currently trace to NVD as the sole source in our pipeline, without independent corroboration — confidence on severity is marked medium even though exploitation status itself is well-supported via CISA KEV. No EPSS score is ingested for this CVE yet, and we don’t have exploit-availability detail beyond the KEV listing itself.
Why this matters
RMM platforms like N-central are attractive targets precisely because a single compromised instance can provide an attacker centralized reach into every endpoint the platform manages — a pre-authentication RCE in that management plane is a worst-case scenario for the customers relying on it, not just for N-able itself. Because exploitation requires no authentication, internet-facing N-central deployments running a pre-2026.3.1.14 build should be treated as the highest-priority patch target in this batch, consistent with CVE-2026-84869’s ConnectWise ScreenConnect flaw — both are RMM/remote-support products added to KEV within days of each other in September 2026, a pattern worth flagging for any organization running multiple such tools.
Frequently Asked Questions
What is CVE-2026-86218? A CVSS 9.8 static code injection vulnerability in N-able N-central (all versions before 2026.3.1.14) that allows pre-authentication remote code execution.
Is CVE-2026-86218 being actively exploited? Yes — CISA added it to the Known Exploited Vulnerabilities catalog on September 8, 2026.
What should N-central administrators do? Upgrade to N-central 2026.3.1.14 or later per N-able’s security advisory, and treat any internet-facing N-central instance as high priority given the flaw requires no authentication.
Data sourced from the National Vulnerability Database (NVD) and CISA’s Known Exploited Vulnerabilities (KEV) catalog, aggregated September 12, 2026. See more vulnerability intelligence.