Active Exploitation of Critical N-central Unauthenticated RCE Vulnerability
Successful exploitation of CVE-2026-86218 could allow an unauthenticated attacker to perform remote code execution
Summary
Successful exploitation of CVE-2026-86218 could allow an unauthenticated attacker to perform remote code execution
Affected platforms
The following platforms are known to be affected:
Threat details
Exploitation of CVE-2026-86218
Security researchers have stated they have observed possible exploitation of vulnerability CVE-2026-86218 as a zero-day.
The NHS England National CSOC assesses further exploitation as highly likely.
Introduction
N-able has released a security hotfix for N-central to address vulnerability CVE-2026-86218.
- CVE-2026-86218 - 'Improper neutralization of directives in statically saved code' vulnerability - CVSSv4 base score: 10.0
Remediation advice
N‑central has released Hotfix 4 that supersedes the earlier releases. Affected organisations are strongly encouraged to review the N-central 2026.3 HF4 Release Notes and apply the update as soon as possible.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 7 September 2026 3:18 pm