CVE-2026-86218 is an unauthenticated remote code execution / static code-injection vulnerability in N-able's N-central remote monitoring and management (RMM) platform, exploited in the wild and added to the CISA Known Exploited Vulnerabilities catalogue on 8 September 2026 (CISA KEV). Exploitation is a priority risk for managed-service providers that use N-central as their operational RMM backbone, because a pre-authentication compromise grants administrative control over the fleets of client devices those providers manage. N-able has released patches; the KEV designation makes patching mandatory for US federal agencies within the required window and should prompt MSP fleets globally to treat it as urgent. It is a distinct CVE from the earlier CVE-2026-18556/CVE-2026-18577 N-central flaws that ACSC flagged under active exploitation in Australia in August 2026.
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-86218 |
| Type | Static code injection / pre-auth RCE |
| Exploited | In the wild; added to CISA KEV (2026-09-08) |
| Affected | N-able N-central RMM |
| Source | CISA / The Hacker News โ Tier 1-2/4 |