Knox CVE Database
/
CVE-2026-86218
Critical
9.8

CVE-2026-86218: N-able N-central Static Code Injection Vulnerability

N-able N-central contains a static code injection vulnerability that could allow for pre-authentication remote code execution.

Added to the CISA KEV catalog:
September 8, 2026

Overview

N-able N-central, a widely deployed managed services platform, contains a static code injection flaw that allows a remote attacker to execute arbitrary code on the server without any authentication. All self-hosted deployments running versions before 2026.3.1.14 are affected. Because N-central manages endpoints across customer environments, a compromised server gives an attacker a position from which to reach every device under management.

Vulnerability details

Affected vendor
N-able
Affected product
N-central
Weakness type (CWE)
CWE-96

Static code injection (CWE-96) occurs when an application writes attacker-supplied input into a file or data store that the application later interprets as executable code, without first sanitizing or neutralizing that input. In N-central, this failure exists in a code path that is reachable before any authentication step, meaning the application accepts and persists the malicious input before it has verified who is submitting it. The injected content is subsequently executed by the server, completing the code execution chain entirely through the application's own runtime.


An attacker with network access to the N-central management interface submits a crafted request containing malicious code directives to an unauthenticated endpoint. No credentials, session tokens, or prior foothold are required. Once the injected code executes on the server, the attacker gains full control of the N-central host, with high confidentiality, integrity, and availability impact. Because N-central acts as a management plane for potentially thousands of endpoints, the downstream reach of a successful compromise extends well beyond the server itself.

Severity and impact

9.8
Critical
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality impact
High
Integrity impact
High
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Review N-central server application logs for unexpected write operations to configuration or script files originating from unauthenticated sessions, particularly requests that precede any login event in the audit trail.
  • Check for new or modified files in N-central application directories that were created or altered by the server process outside of a known upgrade or hotfix window, which may indicate persisted injected code.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see References) guidance and CISA’s “Forensics Triage Requirements” (see References). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
September 11, 2026

Additional hardening

  • Upgrade self-hosted N-central deployments to build 2026.3.1.14 (Hotfix 4) immediately; hosted NCOD instances were patched automatically and require no action.
  • Restrict network access to the N-central management interface to known administrator source addresses using firewall rules or network access controls, reducing the attack surface for unauthenticated endpoints.
  • If immediate patching is not possible, isolate the N-central server from direct internet exposure and require VPN or jump-host access for all management interface connections.
  • Audit managed endpoint agent configurations and credentials stored in N-central for signs of unauthorized access or modification, as a compromised server may have been used to pivot to managed devices.

Key dates

Published (NVD)
September 5, 2026
Added to CISA KEV
September 8, 2026
Remediation deadline
September 11, 2026
Last updated
September 9, 2026

References

Frequently asked questions

Does CVE-2026-86218 affect my FedRAMP authorization?

If N-able N-central runs inside your authorization boundary, yes. CVE-2026-86218 appears on CISA's Known Exploited Vulnerabilities (KEV) catalog, and its remediation deadline of September 11, 2026 has already passed. For a FedRAMP-authorized service, an unpatched KEV in your boundary is a finding. An overdue one is a finding your assessor and sponsoring agency can see now. Your options are to remediate it immediately or formally document the mitigation and the delay.

How does Knox help me handle CVE-2026-86218?

Knox does not patch your software. Remediating N-able N-central is your responsibility under the FedRAMP shared-responsibility model. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, plus continuous compliance monitoring and audit-artifact coverage that support documentation of the fix for your next assessment. Applying the patch is yours to own; managing your compliance posture while you do it is not something you have to handle alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on an ongoing basis. That means exposure like CVE-2026-86218 surfaces during continuous monitoring, not only when an assessor flags it at scheduled review time, giving you a shorter window between disclosure and awareness.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

CVE-2026-86218's remediation deadline of September 11, 2026 has passed. What happens now?

An unremediated CVE-2026-86218 is already a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what turns a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Closing it out now and documenting why the deadline was missed is what keeps your authorization intact and the agency relationship in good standing.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.