CVE-2026-86218
KEV EPSS 0.7%KEV confirmation, vendor hotfix, active exploitation claims credible; CVSS score variance (10.0 vs 0.0 in posts) adds minor noise.
What: N-central pre-authentication remote code execution affecting versions before 2026.3.1.14; CISA KEV-listed as actively exploited.
Why it matters: Added to CISA's Known Exploited Vulnerabilities catalog on 2026-09-08; vendor N-able released Hotfix 4; multiple posts confirm active in-the-wild exploitation targeting enterprise perimeter devices; CISA deadline imposed for federal agencies.
Where it's seen: Security digests, threat intelligence feeds, and urgent patching advisories across Bluesky; vendor acknowledgment and hotfix release documented; CISA KEV alert circulating; defenders mobilizing for immediate remediation.
RISK: CRITICAL — Pre-auth RCE, KEV-listed, active exploitation, federal mandate, zero EPSS indicates early stage.
Description
N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.