CVE-2026-86218Critical· 9.8▾ Hadal⚠ Exploited in the wildPoC availableN-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.
▾ Hadal zone — Critical and actively exploited (CISA KEV / 0day)
impact 53.9 · likelihood 1.5 · exploitation 25
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 2 sources. Availability, not in-the-wild use.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 6.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.4%
Federal remediation due Sep 11, 2026
Last analysed / modified upstream
0.4% → 7.5%
2 GitHub repos · Nuclei ×1 (last check)
Added to the CISA catalog on Sep 8, 2026. Federal remediation due Sep 11, 2026. View catalog ↗
N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.
n-central < 2026.3n-central = 2026.3Upgrade past the affected range:
n-central 2026.3Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-86206Medium· 6.9A vulnerability in the N-central internal API access control filter allows unauthorised access to internal APIs
CVE-2026-86207High· 7.7An authentication bypass in N-central < 2026.3 HF 3 leads to authentication bypass in internal only APIs
CVE-2025-68624Medium· 4.3N-able Mail Assure through April 2026 contains a design-level authorization flaw that allows an authenticated SMTP user to send outbound email using MAIL FROM addresses belonging to other tenants
CVE-2026-68489High· 8.7Static Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js Toolkit" before 2.5.0 allows remote authenticated users to execute arbitrary code as root via custom environment variables.