N-central unauthenticated RCE, exploited (CVE-2026-86218) [PoC]
CVE-2026-86218
CVE-2026-86218: Pre-auth RCE in N-central before 2026.3.1.14, CVSS 10.0, actively exploited. Upgrade to 2026.3.1.14 or later immediately to block attacks.
Actively exploited in the wild - CVE-2026-86218 is a critical pre-authentication remote code execution vulnerability in N-central versions before 2026.3.1.14 that grants unauthenticated attackers full remote code execution on the server. Patched in N-central 2026.3.1.14; update immediately.
Overview
CVE-2026-86218 affects N-central, the network monitoring and management platform from N-able. The vulnerability allows an attacker with network access to the N-central web interface to execute arbitrary code on the underlying server before any authentication occurs. With a CVSS score of 10.0 and no user interaction required, this is the most severe classification possible.
The flaw exists in a pre-authentication code path, meaning no valid credentials are needed to trigger it. An attacker who reaches the N-central management port can compromise the entire platform.
Impact
Successful exploitation gives the attacker remote code execution with the privileges of the N-central service account, which typically runs with elevated system rights. From there, the attacker can:
- Deploy ransomware or persistent backdoors across the N-central host
- Access monitored endpoints, since N-central stores credentials and agent deployment keys for all managed devices
- Steal configuration data, backup credentials, and customer network information
- Pivot to other systems on the internal network
Because N-central manages IT infrastructure for thousands of endpoints, a single compromise can cascade into wholesale network takeover of every monitored device. Though CISA has confirmed active exploitation, the EPSS score of 0.4% suggests attacks remain targeted rather than opportunistic scanning campaigns.
Remediation
N-able has released N-central version 2026.3.1.14, which resolves CVE-2026-86218. Upgrade all affected installations to this version or later without delay.
Until the patch is applied:
- Restrict network access to the N-central web interface to trusted administrative networks only. Do not expose it directly to the internet.
- Enable multi-factor authentication (MFA) for all administrative accounts as a defense-in-depth measure, even though this vulnerability requires no credentials.
- Review N-central server logs for unusual or unexpected connections, especially from unknown source IPs.
- Check for unauthorized new user accounts or scheduled tasks on the N-central host.
- Monitor for any outbound connections from the N-central server that are not expected behavior.
See the N-able security advisory for platform-specific upgrade instructions and checksums.
Security Insight
N-central’s agent-based architecture makes it a high-value target: it holds the keys to every endpoint it manages. This pre-auth RCE, combined with confirmed exploitation, mirrors the 2021 Kaseya VSA supply-chain attack where a single RMM compromise encrypted 1,500 downstream businesses. The pattern is consistent: remote management platforms with internet-exposed interfaces attract chained attacks because one foothold grants a complete fleet compromise. Organizations using N-central should treat this patch urgency as proportional to the blast radius of their entire managed network, not just the N-central server itself.
Data breach reports are available at breach reports and cybersecurity news at security news.
Further Reading
Never miss a critical vulnerability
Get real-time security alerts delivered to your preferred platform.
Public PoC References
Unverified third-party code
These repositories are publicly listed on GitHub and have not been audited by Yazoul Security. They may contain malware, backdoors, destructive payloads, or operational security risks (telemetry, exfiltration). Treat them as hostile binaries. Inspect source before execution. Run only in isolated, disposable lab environments (offline VM, no credentials, no production data).
Authorized use only. This information is provided for defensive research, detection engineering, and patch validation. Using exploit code against systems you do not own or do not have explicit written permission to test is illegal in most jurisdictions and violates Yazoul's terms of use.
| Repository | Stars |
|---|---|
| HORKimhab/CVE-2026-86218 CVE-2026-86218 - Draft or TODO - N-central is vulnerable to a pre-auth remote code execution | ★ 0 |
Showing 1 of 1 known references. Source: nomi-sec/PoC-in-GitHub.
Related Advisories
Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1....
Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. A...
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation....
MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint c...