Junglewise Threat Intelligence

CVE-2026-86218: N-able N-central static code injection vulnerability

CVE-2026-86218 · Severity: critical · Exploited in the wild · Published 2026-09-08

Executive brief

N-able N-central is a widely-deployed remote management and monitoring platform used by managed service providers to manage customer IT infrastructure. An unauthenticated attacker can exploit a code injection flaw to execute arbitrary code on affected systems without needing valid credentials, leading to complete system compromise and potential lateral movement across managed networks.

Technical details

N-able N-central is vulnerable to a static code injection attack that allows pre-authentication remote code execution. The vulnerability exists in the application logic that processes user input without proper sanitization or validation, enabling an attacker to inject arbitrary code that is executed on the server. The attack vector is network-based and requires no authentication or user interaction. Successful exploitation grants an attacker the ability to execute arbitrary code with the privileges of the N-central application, potentially leading to complete compromise of the management platform and all connected systems. No patch information is currently available from the advisory, though the vulnerability has been documented as actively exploited in the wild as of the publication date.

Affected products

  • N-able N-central

Timeline

  • 2026-09-08: disclosed
  • exploited: Actively exploited in the wild

Related threats