Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3344 articles · 210946 vulns · 37/41 feeds (7d)
← Back to list
—
CVE-2026-86218KEVEXPLOITEDPATCHED
n-able · n-central

pre-authentication remote code execution

Description

N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.

Affected Products

VendorProductVersions
n-ablen-central0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
n-ablen-centralcert_advisory90%

References

  • https://me.n-able.com/s/security-advisory/aArVy0000002Ld3KAE/cve202686218-preauthentication-remote-code-execution(vendor-advisory)

Related News (2 articles)

Tier B
BSI Advisories4h ago
[NEU] [hoch] N-able N-Central: Mehrere Schwachstellen ermöglichen Offenlegung von Informationen
→ No new info (linked only)
Tier C
VulDB1d ago
CVE-2026-86218 | N-able N-central up to 2026.3.1.13 privileges management
→ No new info (linked only)

Discussion (0)

Loading…

CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
2026.3.1.14
CWECWE-96
PublishedSep 6, 2026
Trending Score114🔥
Source articles2
Independent2
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-86206
Access control filter bypass allows unauthorised access to APIs
Trending: 35
NONECVE-2026-86207
Authentication bypass leads to unauthorised access to N-central
Trending: 35
NONECVE-2026-18577
Incomplete patch leads to administrative account takeover
Trending: 2
NONECVE-2026-15580
PassPortal browser extension: vault token disclosure via unvalidated postMessage
Trending: 2
NONECVE-2026-18556
Unauthenticated administrative account takeover
Trending: 1

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 6, 2026
Added to CISA KEV
Sep 6, 2026
Discovered by ZDM
Sep 6, 2026
Actively Exploited
Sep 7, 2026
Patch Available
Sep 7, 2026