CVE-2026-86218
pre-authentication remote code execution
N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.
Coverage 2 sources
-
2026-09-07
Help Net Security
critical
N-able patches critical N-central zero-day exploited in the wild (CVE-2026-86218)
N-able patches a critical zero-day RCE flaw in N-central, exploited in the wild.
-
2026-09-08
CISA Cybersecurity Advisories
high
CISA Adds Four Known Exploited Vulnerabilities to Catalog
CISA added four new vulnerabilities to its Known Exploited Vulnerabilities Catalog, indicating active exploitation.
Mentioned with
CVE-2026-75650 CVE-2026-81963 CVE-2026-85880
Also covered
- CVE-2026-86950 Apple iOS and iPadOS
- CVE-2023-6548 Cloud Software Group NetScaler ADC
- CVE-2023-25608 Fortinet FortiAP-W2
- CVE-2026-88772 Memory overflow vulnerability leading to Remote Code Execution or Denial of Service
- CVE-2026-88771 A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands