CuraSec

Act active

N-able N-central Pre-Auth RCE (CVE-2026-86218) Exploited, KEV Listed

2026-09-10 14:58 UTC · The Hacker News · read the source ↗ #rce#rmm#cisa-kev
  • Engineer — Act: CVSS 10.0 pre-auth RCE on N-central is CISA KEV-listed with active exploitation and a public GitHub PoC — patch N-central immediately and audit your N-central server logs for signs of compromise before the patch is applied.
  • SOC/IR — Act: Active exploitation of an RMM platform is a high-priority assume-breach scenario; hunt for anomalous commands or lateral movement originating from N-central agents across managed endpoints since exploitation requires no credentials and leaves a narrow pre-auth detection window.
  • Leader — Act: Compromised RMM tools give attackers keys to every managed endpoint — confirm whether your organization or any MSP you rely on runs N-central, and request written patch confirmation or an attestation of remediation given the September 11 CISA deadline.
  • Signals: CVE-2026-86218 — CISA KEV: listed, EPSS 0.01, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.