N-able's two documents disagreed about exploitation. CISA has settled it
CVE-2026-86218 is a CVSS 10.0 pre-authentication RCE in N-central, patched in the fourth hotfix in five weeks. For two days the vendor's release notes and its incident notice said opposite things about whether it was being exploited. CISA added it to the KEV catalogue on 8 September with a three-day federal deadline.
