Threat Advisory

N-central Flaw Grants Pre-authenticated Remote Code Execution

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A critical-CVSS-rated vulnerability, CVE-2026-86218 with a CVSS score of 9.8, was discovered in N-central server and could allow for pre-authenticated remote code execution. This flaw type is a zero-day vulnerability that poses significant business impact by enabling an attacker to gain pre-authenticated access to the N-central server. The attack vector is remote, allowing attackers to exploit this vulnerability from anywhere. Upgrading from legacy versions is supported via direct upgrades or through intermediate builds.

RECOMMENDATION:

We recommend you to upgrade N-central to version 2026.3.1.14.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A critical-CVSS-rated vulnerability, CVE-2026-86218 with a CVSS score of 9.8, was discovered in N-central server and could allow for pre-authenticated remote code execution. This flaw type is a zero-day vulnerability that poses significant business impact by enabling an attacker to gain pre-authenticated access to the N-central server. The attack vector is remote, allowing attackers to exploit this vulnerability from anywhere. Upgrading from legacy versions is supported via direct upgrades or through intermediate builds.

RECOMMENDATION:

We recommend you to upgrade N-central to version 2026.3.1.14.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu