N-able N-central CVE-2026-86218 enters KEV: deploy HF4 and investigate
Published 10 Sep 2026 · Severity: critical
CISA added CVE-2026-86218 to its Known Exploited Vulnerabilities catalog on 8 September 2026, confirming active exploitation of the N-central pre-authentication remote-code-execution flaw. This is a new exploitation-status event, not a new disclosure. N-able 2026.3 HF4, build 2026.3.1.14, supersedes HF3 and earlier builds; self-hosted customers should upgrade immediately, while N-able says hosted NCOD instances are already patched. Because CISA marks forensic triage as required for in-scope assets, exposed deployments should be investigated as well as patched. N-able's release notes had stated that it had no confirmation of production exploitation, while Huntress separately reported incident evidence; preserve that chronology rather than treating the statements as contemporaneous contradictions.