N-able's release notes say it is not exploited. N-able's incident notice says it is
2026-09-07Security
CVE-2026-86218 is a CVSS 10.0 pre-authentication RCE in N-central, patched on Saturday in the fourth hotfix in five weeks and one day after the third. Two of N-able's own documents disagree about whether it is being exploited in the wild, and the company has not said which is current.