CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

N-able security advisory (AV26-885) – Update 2

unknownknown exploitedpublic exploitCVE-2026-86218CVE-2026-86207
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Serial Number: AV26-885 Date: September 8, 2026 Updated: September 9, 2026 As of September 6, 2026, N-able is affected by vulnerabilities in the following product: N-central Prior to 2026.3.1.14 N-able indicates that CVE-2026-86218 is being exploited in the wild. Update 1 On September 8, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-86218 to their Known Exploited Vulnerabilities (KEV) Database. Update 2 Open-source reporting indicates that CVE-2026-86207 is being exploited in the wild. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. N-central 2026.3 Hotfix 4 – CVE-2026-86218 2026.3 HF4 Release Notes Release Notes | N-able Status | N-able Status Page CISA KEV: CVE-2026-86218

Details

Source
Canadian Centre for Cyber Security (CA · national-cert · site)
Severity
unknown
Published
2026-09-09
Exploitation
Observed in the wild (CISA KEV)

Original advisory: https://cyber.gc.ca/en/alerts-advisories/n-able-security-advisory-av26-885

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-86218coverage & exploitation statusNVD · CVE.org
CVE-2026-86207coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from Canadian Centre for Cyber Security