The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 11, 2026.
The vulnerability in question is CVE-2026-86218 (CVSS score: 10.0), which has been described as a case of static code injection. It has been patched in N-central 2026.3 Hotfix 4, released on September 5, 2026.
“N-able N-central contains a static code injection vulnerability that could allow for pre-authentication remote code execution,” CISA said.
The development came shortly after Huntress said it commenced an investigation following the compromise of a customer’s fully patched N-central production environment on September 4, 2026.


Leave a Reply