Skip to content

CVE-2026-86218

N-central pre-authentication remote code execution enables unauthorised code execution (CVE-2026-86218)

Critical 10.0 KEV Published · Updated

N-central before 2026.3.1.14 has a pre-authentication remote code execution vulnerability, CVE-2026-86218, rated CVSS 4.0 critical (10). CISA KEV lists it as actively exploited. Apply the fixed release N-central 2026.3.1.14 immediately.

What happened

CVE-2026-86218 is a pre-authentication remote code execution flaw in N-central. An attacker who can reach an affected N-central service over the network can exploit it without credentials and without any user interaction. The CVSS 4.0 vector records low attack complexity, no privileges required, no user interaction, and high impact to confidentiality, integrity and availability of the affected system and subsequent systems. The score is 10, critical.

Exploitation status is established by CISA: the KEV catalogue lists CVE-2026-86218 as actively exploited, added on 2026-09-08 with a required-action due date of 2026-09-11, and CISA SSVC records exploitation as active. Ransomware use is recorded as unknown. The CVE record marks the exploitation as not publicly disclosed.

Who is affected

All N-central releases before 2026.3.1.14 are affected. This includes any N-central deployment that is reachable from the internet or another untrusted network, because the vulnerability can be exploited without authentication. Organisations should treat unpatched N-central instances as exposed until they are updated to the fixed release or removed from network reachability.

What to do now

  1. Identify all N-central installations running a release before 2026.3.1.14, especially any reachable from the internet.
  2. Apply the fixed release: N-central 2026.3.1.14.
  3. If immediate update is not possible, restrict network access to affected N-central services to trusted management networks or VPNs until the update can be applied. This is containment, not a replacement for the fixed release.
  4. Confirm the CISA KEV required action for CVE-2026-86218: apply mitigations in accordance with vendor instructions, evaluate each asset's internet exposure, and follow applicable CISA BOD 26-04 guidance. The KEV due date was 2026-09-11.

How to detect it

The CVE record and the CISA KEV entry do not list vendor-published indicators of compromise. Because the vulnerability is pre-authentication and network-reachable, begin by identifying every N-central instance on an affected release that is reachable from the internet or another untrusted network. Treat those instances as exposed until updated to N-central 2026.3.1.14.

Beyond the patch

The KEV record changes the priority here: this is not just a patchable CVSS 10, it is an actively exploited pre-authentication flaw. Managed Detection & Response (MDR) can provide visibility for post-exploitation activity across affected networks, and an Incident Response Retainer makes response capacity available before an incident is confirmed. Because the flaw is reachable over the network without credentials, Virtual CISO Services (vCISO) can help review how management products such as N-central are exposed and decide what compensating controls to put in place.

Affected and fixed versions

ProductAffectedFixed in
N-central– < 2026.3.1.142026.3.1.14

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.