Act
active
N-able N-central Pre-Auth RCE (CVE-2026-86218) Exploited, KEV Listed
- Engineer — Act: CVSS 10.0 pre-auth RCE on N-central is CISA KEV-listed with active exploitation and a public GitHub PoC — patch N-central immediately and audit your N-central server logs for signs of compromise before the patch is applied.
- SOC/IR — Act: Active exploitation of an RMM platform is a high-priority assume-breach scenario; hunt for anomalous commands or lateral movement originating from N-central agents across managed endpoints since exploitation requires no credentials and leaves a narrow pre-auth detection window.
- Leader — Act: Compromised RMM tools give attackers keys to every managed endpoint — confirm whether your organization or any MSP you rely on runs N-central, and request written patch confirmation or an attestation of remediation given the September 11 CISA deadline.
- Signals: CVE-2026-86218 — CISA KEV: listed, EPSS 0.01, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.