criticalKEV
CVE-2026-86218
N-able N-central pre-authentication remote code execution (CVSS 10.0, actively exploited)
- Severity
- critical
- Affected product
- N-able N-central
- Affected versions
- N-able N-central < 2026.3.1.14
- Fixed in
- N-able N-central 2026.3.1.14
- CISA KEV
- Listed as a known exploited vulnerability
- Added to NewScan
- 2026-09-09
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
APPLIANCE FINGERPRINT
NewScan fingerprints the N-able N-central appliance and reports this CVE when the detected version falls inside the affected range below.
Added 2026-09-09 from CISA KEV. N-central before 2026.3.1.14 is vulnerable to pre-authentication remote code execution. Advisory only on today's engine: the existing GET /dms/logins/login_form.php fingerprint exposes distinctive N-central/N-able markers but no version, so NewScan names the CVE and asks the operator to confirm the patch level rather than claiming a verified vulnerable build.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →