← All CVEs NewScan detects
criticalKEV

CVE-2026-86218

N-able N-central pre-authentication remote code execution (CVSS 10.0, actively exploited)

Severity
critical
Affected product
N-able N-central
Affected versions
N-able N-central < 2026.3.1.14
Fixed in
N-able N-central 2026.3.1.14
CISA KEV
Listed as a known exploited vulnerability
Added to NewScan
2026-09-09
Detected by
NewScan — free, self-hosted

How NewScan reports it

APPLIANCE FINGERPRINT

NewScan fingerprints the N-able N-central appliance and reports this CVE when the detected version falls inside the affected range below.

Added 2026-09-09 from CISA KEV. N-central before 2026.3.1.14 is vulnerable to pre-authentication remote code execution. Advisory only on today's engine: the existing GET /dms/logins/login_form.php fingerprint exposes distinctive N-central/N-able markers but no version, so NewScan names the CVE and asks the operator to confirm the patch level rather than claiming a verified vulnerable build.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →