Skip to content
feed: live
>_0dayNews
cisa kev
● Breaking

CISA Adds N-able N-central Auth Bypass to KEV

CISA added a maximum-severity pre-auth RCE in N-able N-central to its KEV catalog on September 9. N-able patched it; audit deployments for new user accounts.

CISA Adds N-able N-central Auth Bypass to KEV
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
airgapMorgan "airgap" Reyes·Published ·1 min read

Confirmed. CISA added a maximum-severity pre-authentication remote code execution flaw in N-able N-central to its Known Exploited Vulnerabilities catalog on September 9, per The Hacker News. The vulnerability is being actively exploited in the wild.

N-able has released a patch. If it hasn’t been applied: apply it now.

What’s in N-central, and why it matters

N-central is an IT infrastructure management platform. Managed service providers use it to remotely monitor and administer client environments. A pre-auth RCE in a platform with that level of access is a direct path into downstream client networks, not just the MSP’s own systems.

SecurityWeek reports that N-able advises administrators to check their deployments for newly created user accounts they don’t recognize. That’s the forensic indicator. If you’ve patched but haven’t audited accounts, the audit is the next step.

Rapid7’s parallel disclosure

Separately, on September 8, Rapid7 Labs published an advisory disclosing two additional authentication bypass vulnerabilities in N-central: CVE-2026-86206 and CVE-2026-86207. Rapid7 found these while investigating the earlier N-central authentication bypass tracked as CVE-2026-18577 (CVSS 8.1, high), which CISA added to KEV in August 2026 following active exploitation.

CVE-2026-86206 and CVE-2026-86207 affect the latest version of N-central and are now patched per Rapid7’s advisory.

Confidence: CISA KEV addition and active exploitation confirmed per The Hacker News. Rapid7 advisory details sourced directly from Rapid7 Labs. CVSS scores for CVE-2026-86206 and CVE-2026-86207 have not yet been published in NVD at time of writing.

Immediate actions

N-able has not publicly posted detailed exploitation indicators beyond the account-creation artifact noted by SecurityWeek. The recommended sequence:

  1. Apply N-able’s patch for the KEV-listed vulnerability.
  2. Update to a version that includes the CVE-2026-86206 and CVE-2026-86207 fixes per Rapid7’s advisory.
  3. Audit all N-central user accounts for entries that weren’t created by your team.

N-central’s position as an MSP management hub makes exploitation high-value: one compromised instance can provide lateral access into multiple client environments.


Related: CISA Adds Seven Exploited Flaws to KEV Catalog | Microsoft Patches Record 974 Vulns, 2 Zero-Days | Adobe Patches StyleSmuggler, CVSS 10 Magento Zero-Day | What Is the CISA KEV Catalog?

Related CVEs
  • [ HIGH ]CVE-2026-18577N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

Found this useful? Share it.