[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2026-86218":6},{"stargazers_count":4,"fetched_at":5},7,"2026-09-07T11:55:15.057Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":69,"aliases":70,"duplicate_of":9,"upstream":71,"downstream":72,"duplicates":73,"related":74,"reserved_at":9,"published_at":75,"modified_at":75,"state":76,"summary":77,"references_raw":86,"kevs":93,"epss":94,"epss_history":97,"metrics":99,"affected":106},"CVE-2026-86218","N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":9,"capec":18},"CWE-96","Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')","The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes code syntax before inserting the input into an executable resource, such as a library, configuration file, or template.","weakness","Draft","Base",[19,53,57,61,65],{"id":20,"name":21,"techniques":22},"CAPEC-35","Leverage Executable Code in Non-Executable Files",[23,34,41],{"id":24,"name":25,"tactics":26,"countermeasures":33},"T1027.006","HTML Smuggling",[27,30],{"id":28,"name":29},"TA0030","Defense Evasion",{"id":31,"name":32},"TA0005","Stealth",[],{"id":35,"name":36,"tactics":37,"countermeasures":40},"T1027.009","Embedded Payloads",[38,39],{"id":28,"name":29},{"id":31,"name":32},[],{"id":42,"name":43,"tactics":44,"countermeasures":47},"T1564.009","Resource Forking",[45,46],{"id":28,"name":29},{"id":31,"name":32},[48],{"id":49,"name":50,"tactic":51},"D3-FFV","File Format Verification",{"name":52},"Isolate",{"id":54,"name":55,"techniques":56},"CAPEC-73","User-Controlled Filename",[],{"id":58,"name":59,"techniques":60},"CAPEC-77","Manipulating User-Controlled Variables",[],{"id":62,"name":63,"techniques":64},"CAPEC-81","Web Server Logs Tampering",[],{"id":66,"name":67,"techniques":68},"CAPEC-85","AJAX Footprinting",[],[],[],[],[],[],[],"2026-09-06T02:15:28.824Z","Received",{"cisa_kev":78,"cisa_ransomware":78,"cisa_vendor":9,"epss_severity":79,"epss_score":80,"severity":81,"severity_score":82,"severity_version":83,"severity_source":84,"severity_vector":85,"severity_status":76},false,"low",0.00411,"critical",10,"v4.0","cve.org","CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",[87],{"url":88,"sources":89,"tags":91},"https://me.n-able.com/s/security-advisory/aArVy0000002Ld3KAE/cve202686218-preauthentication-remote-code-execution",[84,90],"nvd",[92],"Vendor Advisory",[],{"date":95,"score":80,"percentile":96},"2026-09-06",0.3432,[98],{"date":95,"score":80,"percentile":96},[100,103],{"source":84,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":9,"cvss_v4_0":101},{"baseScore":82,"baseSeverity":102,"vectorString":85,"impactScore":9,"exploitabilityScore":9},"CRITICAL",{"source":90,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":9,"cvss_v4_0":104},{"baseScore":82,"baseSeverity":102,"vectorString":105,"impactScore":9,"exploitabilityScore":9},"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",[107],{"ecosystem":9,"name":108,"vendor":109,"product":110,"cpe_part":111,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":112},"N-central","n-able","n-central","a",[113],{"version":114,"is_range":115,"range_type":84,"version_start":9,"version_start_type":9,"version_end":116,"version_end_type":117,"fixed_in":9},"\u003C 2026.3.1.14",true,"2026.3.1.14","excluding"]