N-central Pre-Authentication Remote Code Execution
Pre-authentication remote code execution in N-able N-central via static code injection. Network-accessible, no credentials required. Fixed in 2026.3.1.14.
- Vendor
- N-able
- Product
- N-central
- CVSS
- 10.0
- EPSS (exploit probability)
- 12.9%
- Status
- kev
- CISA patch-by (BOD 22-01)
- Published
N-able’s N-central remote monitoring and management platform contains a pre-authentication remote code execution vulnerability in all versions before 2026.3.1.14. Classified as CWE-96 (static code injection), the flaw allows an unauthenticated attacker with network access to the server to execute arbitrary code on the host. No credentials and no user interaction are required.
N-central is a remote monitoring and management (RMM) platform used by managed service providers (MSPs) to oversee the IT environments of multiple client organizations from a single management console. An MSP running N-central typically has privileged agent access to dozens or hundreds of client endpoints. Unauthenticated RCE on the N-central server gives an attacker access that extends across the whole managed fleet, not just the management server itself. RMM platforms are high-value targets for ransomware operators for exactly this reason: a single compromised console can reach every organization the MSP manages.
Static code injection (CWE-96) occurs when user-controlled or externally reachable input is written to persistent storage and later executed by the application, without the application treating that stored content as inert data. In N-central’s case, an unauthenticated network request can supply input that the server subsequently executes as code, with no authentication gate in the path.
The vulnerability is scored at CVSS 4.0: 10.0, the maximum, with a fully network-accessible attack vector (AV:N), low attack complexity (AC:L), no privileges required (PR:N), and no user interaction (UI:N). All confidentiality, integrity, and availability impact dimensions are rated high for both the vulnerable system and downstream managed endpoints.
N-able released version 2026.3.1.14 to address the flaw. No workarounds are documented in the advisory. Instances that cannot immediately receive the update should be isolated from external network access while the patch is staged.
CISA added CVE-2026-86218 to the Known Exploited Vulnerabilities catalog on September 8, 2026 with a remediation deadline of September 11, under BOD 26-04. The three-day window is the shortest of the four CVEs added to KEV on September 8, reflecting the broad attack surface of an internet-facing RMM platform with access to many client environments.
CISA added three other vulnerabilities in the same September 8 KEV batch: CVE-2026-75650, a CVSS 10.0 template-engine injection in Adobe Commerce; CVE-2026-81963, a Windows Update Stack link-following privilege escalation; and CVE-2026-85880, a Windows ALPC heap buffer overflow that allows AppContainer sandbox escape. The Windows CVEs carry CVSS 7.8 ratings and a September 22 remediation deadline; the N-central and Adobe CVEs both carry CVSS 10.0 with a September 11 deadline.
See the full coverage article for context on the exploitation risk in MSP environments.
