HackMyIP
← Back to News
2026-09-09 The Hacker News

CISA Flags Critical N-able N-central RCE Flaw Actively Exploited

VulnerabilityZero-DayIncident Response

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a maximum-severity vulnerability impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog, mandating that Federal Civilian Executive Branch (FCEB) agencies apply patches by September 11, 2026. The flaw, tracked as CVE-2026-86218 with a CVSS score of 10.0, is a static code injection vulnerability enabling pre-authentication remote code execution. N-able addressed the issue in N-central 2026.3 Hotfix 4, released on September 5, 2026, and has confirmed that the bug is being actively weaponized in the wild.

The advisory follows an investigation launched by Huntress on September 4, 2026, after a fully patched N-central production environment belonging to one of its customers was compromised. Due to limited historical logging on the appliance, Huntress cannot definitively confirm whether the attacker exploited CVE-2026-86218 or chained two related flaws, CVE-2026-86206 and CVE-2026-86207, which were patched simultaneously in N-central 2026.3 Hotfix 3. According to Rapid7 researcher Stephen Fewer, who discovered and reported those two bugs, they can be combined to bypass authentication and create a new attacker-controlled System Administrator account on affected servers. Organizations running exposed N-central instances should immediately verify patch status and audit administrative accounts for unauthorized additions. Security teams can use a port scanner to identify any internet-exposed N-central appliances and confirm they are not listening on default management ports to external networks.

In an urgent customer notice, N-able stated that CVE-2026-86218 "has been observed being exploited in the wild" and confirmed it is actively investigating while implementing additional protective measures. Administrators are strongly urged to apply the latest hotfix without delay, review logs for indicators of compromise, and rotate all System Administrator credentials. Given the authentication-bypass component of the chained vulnerabilities, defenders should also verify account integrity by cross-referencing credentials against known exposures using an password checker and monitor for anomalous session activity. For organizations evaluating the broader attack surface, a WHOIS lookup on suspicious infrastructure can assist in attributing scanning or exploitation activity tied to the campaign.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

My IP →IP Lookup →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →