CVE-2026-86206 affects N-able N-central, a remote monitoring and management (RMM) platform widely used by managed service providers. NVD classifies it as CWE-791 (Incomplete Filtering of Special Elements). Our source data does not carry a CVSS score for this CVE as of our ingestion. VulnCheck’s KEV feed reports the CVE as exploited, dated September 10, 2026.
That exploitation report is single-sourced. CISA has not added CVE-2026-86206 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion. No Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.
What the flaw is
NVD’s description for this CVE is brief: a vulnerability in N-central’s internal API access-control filter allows unauthorized access to internal APIs. NVD does not name the specific filter logic or which internal APIs are reachable as a result; N-able’s own security advisory, cited in NVD’s reference list, is the authoritative technical source, but our source data does not carry deeper mechanism detail from it. The issue is fixed in N-central 2026.3 HF3 and 2026.4.
Evidence and confidence
- Medium confidence — the CWE-791 classification and the fixed-version information, which trace to NVD and N-able’s own security advisory. The exploitation report traces to VulnCheck KEV alone.
- Our source data does not carry a CVSS score, vector, or EPSS score/percentile for this CVE.
No field is in conflict between our sources.
Why this matters
N-central is deployed by managed service providers to monitor and manage client infrastructure at scale, which makes any internal-API access-control gap in the platform a potential pivot point into every environment a given N-central instance manages — the same supply-chain-multiplier risk that makes RMM platforms a recurring high-value target. Confirmed exploitation, even without a published CVSS score, is reason enough for N-central operators to prioritize this patch.
Frequently Asked Questions
What is CVE-2026-86206? An access-control bypass (CWE-791) in N-able N-central’s internal API filtering, allowing unauthorized access to internal APIs, fixed in N-central 2026.3 HF3 and 2026.4.
Is CVE-2026-86206 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated September 10, 2026. That report is single-sourced; CISA has not listed this CVE in its own Known Exploited Vulnerabilities catalog as of our current ingestion, and we have no independent corroboration.
Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.
Which version fixes this? N-central 2026.3 HF3 and 2026.4, per NVD and N-able’s own security advisory.
Weakness classification and fix version sourced from the National Vulnerability Database record for CVE-2026-86206 and N-able’s own security advisory. Exploitation status and the September 10, 2026 catalog date reported by VulnCheck KEV. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our current ingestion. No CVSS score or EPSS data was available in our ingestion as of this writing. Aggregated September 20, 2026. See more vulnerability intelligence.