Threat reportVulnerabilityTL-2026-2415
CVE-2026-86218 — Unauthenticated Pre-Auth Remote Code Execution in N-able N-central (Active Exploitation, CISA KEV)
CVE-2026-86218 (TL-2026-2415) is a critical-severity software vulnerability scored CVSS 10, first published 2026-09-09. It has no confirmed attribution, affects N-able N-central (On-Premises), references 1 CVE (CVE-2026-86218), maps to 14 MITRE ATT&CK techniques (T1018, T1021, T1027), and is covered by 9 detection rules and 14 indicators of compromise.
- CVSS
- 10/10Critical
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 14MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 14Indicators of compromise
Key facts for TL-2026-2415
- Threat ID
- TL-2026-2415
- Severity
- CRITICAL
- CVSS
- 10 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- managed-service-providers, enterprise-it, federal-government, information-technology, health
- Target regions
- North America, Europe, australia, Global
- Detection rules
- 9
- Indicators of compromise
- 14
Malware and tooling in CVE-2026-86218
Malware and tooling: CloudFlare Tunnel
How CVE-2026-86218 works
N-able N-central on-premises RMM platform contains a critical pre-authentication static code injection vulnerability (CWE-96) rated CVSS 10.0, allowing unauthenticated remote attackers to execute arbitrary code on the underlying operating system. CISA added CVE-2026-86218 to its Known Exploited Vulnerabilities catalog on September 8, 2026, confirming active in-the-wild exploitation. Huntress reported at least one customer instance compromised before the patch shipped. The vulnerability affects all builds prior to 2026.3.1.14 across release lines 2025.4 through 2026.3, marking the fourth emergency hotfix in five weeks for the platform.
CVE-2026-86218 is a pre-authentication remote code execution vulnerability in N-able N-central, an on-premises remote monitoring and management (RMM) platform widely deployed by Managed Service Providers (MSPs) and enterprise IT organizations. The vulnerability is classified as a static code injection (CWE-96) — improper neutralization of directives in statically saved, executable code — enabling attackers with network access to an exposed N-central HTTP administration interface to achieve unrestricted, remote code execution on the server's operating system without authentication or user interaction.
The flaw was discovered and reported through N-able's responsible disclosure program. N-able released Hotfix 4 (build 2026.3.1.14) on September 5-6, 2026 to address it. Huntress independently confirmed at least one compromised on-premises instance on September 4, 2026 — a server that was fully patched up to the then-current hotfix level — though rotated logs prevented definitive attribution to a specific exploit chain. watchTowr successfully reproduced the exploit and confirmed the pre-auth RCE capability. CISA added the vulnerability to the Known Exploited Vulnerabilities (KEV) catalog on September 8, 2026, mandating that federal civilian agencies apply mitigations by September 11, 2026 under Binding Operational Directive (BOD) 26-04, with forensic triage required for any exposed systems.
N-central is architecturally a Java-based application fronted by an Envoy edge proxy (TCP 8443 by default) passing requests to Jetty, with legacy SOAP API endpoints at /dms/services/ServerUI and /dms/services/ServerMMS. The platform's role as MSP management infrastructure makes it a high-value target — a compromised N-central server provides immediate administrative access to all downstream managed endpoints via built-in remote-control features (Take Control), remote scripting, and software deployment capabilities. The Shadowserver Foundation estimated approximately 1,500 internet-facing N-central instances were potentially exploitable.
Post-exploitation activity observed by Huntress and other responders includes: creation of unauthorized administrative accounts with .invalid email suffixes, deployment of Cloudflare tunnels (cloudflared) as persistent backdoor channels, abuse of the built-in MSP Support account for Take Control sessions, process masquerading (svchost.exe placed in user Documents folders), targeted reconnaissance on Domain Controllers, and use of EDR evasion tooling. The compromise cascade risk is severe: a single N-central server breach can expose hundreds or thousands of downstream client environments to ransomware deployment, data theft, and persistent network access.
This vulnerability is the latest in a cascade of N-central security disclosures. Prior hotfixes in August-September 2026 addressed CVE-2026-18556 and CVE-2026-18577 (authentication bypass, CVSS 8.2, exploited in the wild from August 1, 2026), followed by CVE-2026-86206 (semiolon/Forwarded header parsing discrepancy between Envoy and Jetty, CVSS 6.9) and CVE-2026-86207 (UserTwoFactorLogin authentication bypass via built-in user IDs 1, 50, and 51, CVSS 7.7), both discovered by Rapid7 Labs. CVE-2026-86218 is distinct in requiring no prior access whatsoever — a single HTTP request to an exposed port is sufficient for full compromise.
MITRE ATT&CK techniques used in TL-2026-2415
Discovery
T1018 Remote System Discovery; T1057 Process Discovery
Lateral Movement
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading
Execution
T1059 Command and Scripting Interpreter
Persistence
T1078 Valid Accounts; T1098 Account Manipulation; T1133 External Remote Services; T1543 Create or Modify System Process
Privilege Escalation
Initial Access
T1190 Exploit Public-Facing Application
Command and Control
T1219 Remote Access Tools; T1572 Protocol Tunneling
defense-impairment
Affected products and versions in CVE-2026-86218
- N-able — N-central (On-Premises)
Vulnerable versions: 2025.4 (all builds); 2026.1 (all builds); 2026.2 (all builds); 2026.3 (all builds prior to 2026.3.1.14 including Hotfix 1, 2, and 3)
Fixed in: 2026.3.1.14 (Hotfix 4) - N-able — N-central (NCOD Hosted)
Fixed in: Patched server-side by N-able — no customer action required
Remediation for CVE-2026-86218
Patches
- N-central 2026.3.1.14 (Hotfix 4) — available from N-able customer portal, supersedes all prior hotfixes
Immediate actions
- Upgrade on-premises N-central to build 2026.3.1.14 (Hotfix 4) immediately — HF3 does NOT fix CVE-2026-86218
- Restrict network access to the N-central management console (TCP 8443) to trusted internal IPs only, preferably behind VPN
- Audit all N-central user accounts for anomalous accounts with .invalid email suffixes — these are confirmed post-exploitation artifacts
- Review Take Control session logs for unauthorized remote sessions, particularly from IP address 173.249.252.200 and against the MSP Support default account
- Scan N-central servers for Cloudflared Windows services, svchost.exe in user Documents folders, and msimg32.dll outside C:\Windows\System32
- Review envoy_proxy_HTTPS.log and ncentraldms syslog for URL-encoded anomalies (%2F) and probes to /remoteControlAction.do?method=getPierDetails
Workarounds
- If Hotfix 4 cannot be applied immediately, isolate the N-central server from all internet access and restrict to trusted administrative networks only
- Hosted (NCOD) customers: no action required — N-able patched server-side
Longer-term hardening
- Evaluate migration from on-premises N-central to NCOD (hosted) where feasible — hosted instances were patched server-side by N-able
- Disable legacy SOAP API endpoints (/dms/services/*) if not required for operations
- Deploy network segmentation isolating RMM administration infrastructure from general corporate networks and client environments
- Implement EDR behavioral rules detecting Java server processes (ncentral.jar) spawning interactive shells (bash, sh, python3, perl)
- Establish forensic log retention policies that preserve evidence across patch cycles — Huntress investigation was hindered by log rotation on the compromised appliance
- Deploy 24/7 monitoring of RMM administrative actions, account creation events, and Take Control session initiation from unusual source addresses
CVEs associated with CVE-2026-86218
Weaknesses (CWE) in CVE-2026-86218
Timeline of CVE-2026-86218
- N-able observed a spike in licensing issues on on-premises N-central instances, later determined to be the first signs of exploitation against authentication bypass vulnerabilities (CVE-2026-18556/CVE-2026-18577)
- First confirmed exploitation of N-central vulnerabilities in the wild — attackers gained admin access via authentication bypass and deployed Cloudflare tunnels, remote access tools, and EDR evasion tooling
- Rapid7 Labs contacted N-able regarding two new authentication bypass vulnerabilities (CVE-2026-86206 and CVE-2026-86207) discovered during research on the earlier CVE-2026-18577
- Huntress began investigating a customer's fully-patched N-central production environment that was compromised — the investigation could not definitively rule out CVE-2026-86218 due to rotated appliance logs
- N-able released Hotfix 3 (build 2026.3.1.13) addressing CVE-2026-86206 and CVE-2026-86207 (authentication bypass chain discovered by Rapid7)
- N-able released Hotfix 4 (build 2026.3.1.14) addressing CVE-2026-86218 — the fourth emergency hotfix in five weeks. CVE published in NVD database
- CISA added CVE-2026-86218 to the Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation. Rapid7 and N-able publicly disclosed CVE-2026-86206 and CVE-2026-86207
- Multiple security outlets (The Hacker News, Cybersecuritynews, Meterpreter.org) published comprehensive reporting on CVE-2026-86218 with IOCs, detection guidance, and attack chain analysis. watchTowr confirmed successful exploit reproduction
- CISA BOD 26-04 deadline for federal civilian agencies to apply mitigations for CVE-2026-86218, with mandatory forensic triage for exposed systems
Sources cited for CVE-2026-86218
- CISA Known Exploited Vulnerabilities Catalog — CVE-2026-86218
- NVD Detail — CVE-2026-86218 (CVSS 10.0 / 9.8)
- The Hacker News — N-able N-central Pre-Auth RCE Flaw Added to CISA KEV
- Cybersecuritynews — N-able N-central RCE Vulnerability
- Meterpreter.org — CVE-2026-86218 Technical Breakdown
- Rapid7 — CVE-2026-86206 / CVE-2026-86207 Authentication Bypass Analysis
- Huntress — N-able Vulnerability Exploitation Investigation
- Horizon3.ai — N-able N-central: From N-days to 0-days (Attack Surface Research)
- N-able Status — N-central 2026.3 Hotfix 4 / CVE-2026-86218
- N-able Release Notes — N-central 2026.3 HF4
- CISA BOD 26-04 Implementation Guidance
- Sophos — N-able N-central Exploitation Results in RMM Tool Deployment
- watchTowr — CVE-2026-86218 Reproduction Confirmation (via THN)
- Shadowserver Foundation — Internet-facing N-central Instance Count
Detection coverage for TL-2026-2415
As of 2026-09-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2415 across Splunk SPL, Microsoft KQL and Sigma, covering 14 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.