An unauthenticated remote code execution vulnerability (CVE-2026-86218) in N-able's N-central remote monitoring and management platform has been exploited in the wild and was added to the CISA Known Exploited Vulnerabilities catalogue on 8 September 2026. The flaw gives a pre-authentication attacker administrative control over the platform and, by extension, the fleets of managed devices connected to it โ a priority risk for managed-service providers that run N-central as their RMM backbone. N-able has released patches. The KEV designation drives mandatory US federal patching and should prompt MSP fleets (including in Australia and New Zealand) to treat it as urgent.
| Attribute | Detail |
|---|---|
| Date | 2026-09-08 (KEV add); exploited prior |
| Type | Pre-auth RCE / code injection |
| CVE | CVE-2026-86218 |
| Source | CISA / The Hacker News โ Tier 1-2/4 |
Distinct from the earlier N-central flaws CVE-2026-18556/CVE-2026-18577 that the ACSC flagged under active exploitation in Australia in August 2026.