{"id":2752,"date":"2026-09-09T05:17:13","date_gmt":"2026-09-09T05:17:13","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2752"},"modified":"2026-09-09T05:17:13","modified_gmt":"2026-09-09T05:17:13","slug":"n-able-n-central-pre-auth-rce-flaw-exploited-in-the-wild","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2752","title":{"rendered":"N-able N-central Pre-Auth RCE Flaw Exploited in the Wild"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Sep 09, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ Code Injection<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhMxDWMjpVE5kkeTzvYQ-YAyekZZ6U6CzCYj462wNRwiMna-44-sJo8kY5Nz2-f_D1N7c0lkhR8Hr2BoAvsP6vVb7ea_R5s-UxdKkwnv6apOIM8sIxEoBRQXek7U5lrR0VaP9q_W8hFULVW7qyvskPiGvZN9wyC_FAUm23HdPcLw_wsmfU0-GoQ3PVkNNyJ\/s1700-nu-rw-lo-l85-e365\/n-able.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday <a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2026\/09\/08\/cisa-adds-four-known-exploited-vulnerabilities-catalog\" target=\"_blank\">added<\/a> a maximum-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (<a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\" target=\"_blank\">KEV<\/a>) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 11, 2026.<\/p>\n<p>The vulnerability in question is <strong><a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-86218\" target=\"_blank\">CVE-2026-86218<\/a><\/strong> (CVSS score: 10.0), which has been described as a case of static code injection. It has been patched in <a href=\"https:\/\/documentation.n-able.com\/N-central\/Release_Notes\/GA\/Content\/N-central_2026.3_HF3_Release_Notes.htm\" target=\"_blank\">N-central 2026.3 Hotfix 4<\/a>, released on September 5, 2026.<\/p>\n<p>\u00abN-able N-central contains a static code injection vulnerability that could allow for pre-authentication remote code execution,\u00bb CISA said.<\/p>\n<p>The development came shortly after Huntress said it commenced an investigation following the compromise of a customer&#8217;s fully patched N-central production environment on September 4, 2026.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/trust-world-update-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhYq3TvePXpW0JIC7fXyv7A1W8KQqmb-AZqza2EuPyT0k8Nm5CwHYHISFLKXSKIAyR8JRtqEFQ4zx5jADiAkZKQ08nRWG1jCRV5YAbhKua7WaDdH1L6wsI-xOkoV4brlMfK44UwU-4Q1xqWg0uNN7sZkMCzci4RXYgWMNPHTtuKua7OR4oCbmxE10u0yKnR\/s728-nu-rw-lo-l85-e365\/tl-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>However, it remains unclear if the intrusion involved CVE-2026-86218 or two other vulnerabilities (<a href=\"https:\/\/documentation.n-able.com\/N-central\/Release_Notes\/GA\/Content\/N-central_2026.3_HF4_Release_Notes.htm\" target=\"_blank\">CVE-2026-86206 and CVE-2026-86207<\/a>) that were patched by N-able the same day with N-central 2026.3 Hotfix 3. CVE-2026-86206 and CVE-2026-86207 can be chained together to allow a remote unauthenticated attacker to bypass authentication and create a new attacker-controlled System Administrator account on an affected server, per <a href=\"https:\/\/www.rapid7.com\/blog\/post\/ve-cve-2026-86206-cve-2026-86207-n-able-n-central-authentication-bypass-fixed\/\" target=\"_blank\">Rapid7&#8217;s Stephen Fewer<\/a>, who discovered and reported them.<\/p>\n<p>\u00abDue to limited historical logging available directly on the appliance, we cannot definitively confirm which specific exploit the threat actor used to achieve their compromise, nor can we rule out the use of alternative vulnerabilities,\u00bb Huntress <a href=\"https:\/\/www.huntress.com\/blog\/n-able-vulnerability-exploitation\" target=\"_blank\">noted<\/a>.<\/p>\n<p>In a <a href=\"https:\/\/uptime.n-able.com\/event\/201814\/\" target=\"_blank\">separate \u00aburgent\u00bb notice<\/a> sent directly to customers, N-able said CVE-2026-86218 \u00abhas been observed being exploited in the wild\u00bb and that it&#8217;s \u00abactively investigating this matter and have taken additional steps to help protect customer environments.\u00bb It also urged customers to apply the hotfix immediately. <\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Sep 09, 2026Vulnerability \/ Code Injection The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2753,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[128,70,2847,2848,1040,316,656],"class_list":["post-2752","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-exploited","tag-flaw","tag-nable","tag-ncentral","tag-preauth","tag-rce","tag-wild"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2752","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2752"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2752\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2753"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2752"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2752"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2752"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}