CVE-2026-86218: N-able N-central Static Code Injection Vulnerability
Published Sep 6, 2026
·Updated
N-able N-central contains a static code injection vulnerability that could allow for pre-authentication remote code execution.
Other sources
N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.
— MITRE
Affected Software
7 affected components
N-central<2026.3.1.14
N-able N-Central<2026.3
N-able N-Central=2026.3
N-able N-Central=2026.3-hotfix1
N-able N-Central=2026.3-hotfix2
N-able N-Central=2026.3-hotfix3
N-able N-Central
Event History
Sep 6, 2026
CVE Published
via MITRE·02:15 AM
Data Sourced
via MITRE·02:15 AM
DescriptionWeakness
Data Sourced
via NVD·03:17 AM
DescriptionSeverityWeaknessAffected Software
Sep 8, 2026
Known Exploited
via CISA·12:00 AM
Data Sourced
via CISA·12:00 AM
RemedyDescriptionAffected Software
Frequently Asked Questions
1
What version should I upgrade to?
Upgrade N-central to version 2026.3.1.14 or later. Versions before 2026.3.1.14 are affected.