CVE-2026-86218 | 10.0 Critical | Pre-Authentication Remote Code Execution → Allows an unauthenticated remote attacker to execute arbitrary code on the N-central server via a static code injection flaw

CVE-2026-86218 | 10.0 Critical | Pre-Authentication Remote Code Execution → Allows an unauthenticated remote attacker to execute arbitrary code on the N-central server via a static code injection flaw. → Affects all on-premises N-central builds prior to 2026.3.1.14, including servers already updated to the previous hotfix (2026.3.1.13).

1 reportother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

CVE-2026-86218 | 10.0 Critical | Pre-Authentication Remote Code Execution → Allows an unauthenticated remote attacker to execute arbitrary code on the N-central server via a static code injection flaw

mastodon:infosec-exchangeother21d ago kagi ↗

CVE-2026-86218 | 10.0 Critical | Pre-Authentication Remote Code Execution → Allows an unauthenticated remote attacker to execute arbitrary code on the N-central server via a static code injection flaw. → Affects all on-premises N-central builds prior to 2026.3.1.14, including servers already updated to the previous hotfix (2026.3.1.13).