THREATOPS
THREAT OPSThreat News › N-able N-central Pre-Auth RCE Flaw Exploited in the Wild

N-able N-central Pre-Auth RCE Flaw Exploited in the Wild

medthehackernewsPublished 2026-09-09

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 11, 2026.

The vulnerability in question is CVE-2026-86218 (CVSS score: 10.0), which has been described as a

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://thehackernews.com/2026/09/n-able-n-central-pre-auth-rce-flaw.html