N-able security advisory (AV26-885) – Update 2
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Serial Number: AV26-885 Date: September 8, 2026 Updated: September 9, 2026 As of September 6, 2026, N-able is affected by vulnerabilities in the following product: N-central Prior to 2026.3.1.14 N-able indicates that CVE-2026-86218 is being exploited in the wild. Update 1 On September 8, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-86218 to their Known Exploited Vulnerabilities (KEV) Database. Update 2 Open-source reporting indicates that CVE-2026-86207 is being exploited in the wild. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. N-central 2026.3 Hotfix 4 – CVE-2026-86218 2026.3 HF4 Release Notes Release Notes | N-able Status | N-able Status Page CISA KEV: CVE-2026-86218
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/n-able-security-advisory-av26-885
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation confirmedCVE-2026-86218Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 53% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-862070.73% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 52% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-86218 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-86207 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- criticalexploited[UPDATE] [kritisch] N-able N-Central: Mehrere Schwachstellen ermöglichen Offenlegung von Informationencert-bund
- highexploitedCISA Adds Four Known Exploited Vulnerabilities to Catalogcisa
- criticalexploitedCVE-2026-86218: N-able N-central Static Code Injection Vulnerabilitycisa-kev
- unknownexploitedNCSC-2026-0342 [1.00] [H/H] Kwetsbaarheid verholpen in N-central van N-ablencsc-nl
- criticalexploitedCVE-2026-86218: N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: befo…nvd
- unknownCVE-2026-86207: An authentication bypass in N-central < 2026.3 HF 3 leads to authentication bypass in internal…nvd
More from Canadian Centre for Cyber Security
- unknownFortra security advisory (AV26-906)2026-09-10
- unknownPalo Alto Networks security advisory (AV26-905)2026-09-10
- unknownAL26-019 - Vulnerabilities impacting Citrix NetScaler ADC and NetScaler Gateway - CVE-2026-19490 and CVE-2026-…2026-09-09
- unknownCitrix security advisory (AV26-833) - Update 12026-09-09
- criticalCisco security advisory (AV26-197) – Update 32026-09-09