Called exploited the same day it was disclosed.
Measured from the CVE publication date to the earliest of 3 KEV catalogues that list it.
The life of this vulnerability
- CVE reserved
- CVE published1d
- First KEV listingsame day
- Last KEV listing2d
- Last sighting2d
Gaps are compressed to equal steps. The elapsed time is printed under each.
Which catalogues call it exploited
- CISA KEVUS federallisted Sep 8, 2026
- EUVDENISA, European Unionlisted Sep 8, 2026
- VulnCheck KEVcommercial researchlisted Sep 6, 2026
- CIRCLaggregator, mirrors the abovelisted Sep 6, 2026, not counted
3 catalogues list it. CIRCL aggregates the others and is shown but not counted.
Public exploitation evidence
- reported exploitationuptime.n-able.com/event/201814/
1 public report collected from VulnCheck and CIRCL, first on Sep 6, 2026. Each links to its original source. We have not verified them.
Description
N-able N-central contains a static code injection vulnerability that could allow for pre-authentication remote code execution.
Required action (CISA)
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
