Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/jithinkrishnanrs/cve-2026-86218-n-central-ioc-toolkit
Defensive ToolsIndicator of Compromise (IOC) ManagementVulnerability AnalysisInformation GatheringThreat IntelligenceLearning & EducationIncident ResponseLog Analysis

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
GitHub
jithinkrishnanrs/cve-2026-86218-n-central-ioc-toolkit

CVE-2026-86218-N-central-IOC-Toolkit

Defensive IOC and detection toolkit for CVE-2026-86218, a critical pre-auth RCE in N-able N-central. Includes IOCs, log scanner, Sigma, Splunk, Elastic/KQL detections, and incident response guidance.

View Repository
5h 58m agoNot yet reviewed
Share

CVE-2026-86218 — N-able N-central Pre-Authentication RCE | IOC & Detection Toolkit

CVSS 10.0 (Critical) · Pre-Auth Remote Code Execution · Static Code Injection (CWE-96) · Actively Exploited · CISA KEV

CVSS CISA KEV Status License Maintained

Maintainer: @jithinkrishnanrs · Repo: github.com/jithinkrishnanrs/CVE-2026-86218-N-central-IOC-Toolkit

A community-maintained, defender-focused Indicators of Compromise (IOC) collection, log-hunting scanner, Sigma/Splunk/Elastic detection content, and remediation playbook for — a maximum-severity (CVSS 10.0), vulnerability in , an on-premises and hosted Remote Monitoring and Management (RMM) platform widely used by Managed Service Providers (MSPs).

CVE-2026-86218
unauthenticated remote code execution
N-able N-central

This repository exists to give incident responders, MSP security teams, SOC analysts, and threat hunters a single place to:

  • Understand what CVE-2026-86218 is and how it's being exploited
  • Pull machine-readable IOCs (IPs, domains, account/log patterns) for SIEM, firewall, and EDR ingestion
  • Run a ready-made Python scanner against N-central logs to detect compromise
  • Deploy Sigma, Splunk SPL, and Elastic/KQL detection rules
  • Follow a step-by-step patch & incident-response checklist

⚠️ This is a defensive toolkit. There is no exploit code, PoC, or weaponized payload in this repository. It exists solely to help defenders detect and remediate exploitation of CVE-2026-86218.


Table of Contents

  • Vulnerability Summary
  • Timeline
  • Affected Products & Versions
  • How the Exploit Works
  • Indicators of Compromise (IOCs)
  • Repository Structure
  • Quick Start — Run the IOC Scanner
  • Detection Content
  • Remediation & Patch Guidance
  • Incident Response Checklist
  • Frequently Asked Questions
  • References & Credits
  • Disclaimer
  • Contributing
  • License

Vulnerability Summary

FieldDetail
CVE IDCVE-2026-86218
ProductN-able N-central (on-premises and hosted / NCOD)
Vulnerability TypeStatic Code Injection — Improper Neutralization of Directives in Statically Saved Code
CWECWE-96
CVSS v3.x Score10.0 (Critical)
Attack VectorNetwork
Privileges RequiredNone (pre-authentication)
User InteractionNone
ImpactFull remote code execution as the N-central server process; complete loss of confidentiality, integrity, and availability
Affected VersionsAll N-central builds prior to 2026.3.1.14
Fixed Version2026.3.1.14 (N-central 2026.3 Hotfix 4 / HF4)
Disclosure DateSeptember 6, 2026
Patch Release DateSeptember 5–6, 2026 (Hotfix 4)
CISA KEVAdded to the Known Exploited Vulnerabilities catalog; federal civilian agencies (BOD 22-01) were ordered to remediate by September 11, 2026
Exploited in the WildYes, per N-able's incident notice and CISA. Huntress has not been able to definitively attribute a specific observed intrusion to CVE-2026-86218 specifically due to rotated appliance logs, and N-able's own release notes state there is "no confirmation" of exploitation in production at time of patch — see Detection Notes / Caveats below.
Reported ByIndependent third-party researcher via N-able's responsible disclosure program (distinct from the two CVEs disclosed the day before: CVE-2026-86206 / CVE-2026-86207)
Estimated Internet Exposure~1,500 internet-facing N-central servers (Shadowserver Foundation), concentrated in the US and Europe

Why This Matters for MSPs

N-central is a one-to-many force multiplier. A single compromised N-central server typically holds:

  • Privileged credentials for every managed endpoint across every downstream client
  • Remote script execution / "Take Control" capability over managed servers and workstations, including domain controllers
  • Network topology, asset inventory, and configuration data for all managed environments

A pre-auth RCE against the server itself means an attacker with zero credentials can potentially pivot into every organization the MSP manages — this is why CVE-2026-86218 was scored a perfect CVSS 10.0.


Timeline

Date (2026)Event
Aug 1–2N-able discloses a critical N-central vulnerability (CVE-2026-18556), later clarified as CVE-2026-18577 (incomplete patch for the first). Hotfix 1 (2026.3.1.7) released.
Aug 6Hotfix 2 (2026.3.1.10) released with additional hardening for CVE-2026-18577. Four additional malicious IPs published.
Sep 4Huntress begins investigating a compromised, fully patched N-central production environment.
Sep 5N-able discloses a new, distinct authentication-bypass exploit chain: CVE-2026-86206 and CVE-2026-86207. Hotfix 3 (2026.3.1.13) released.
Sep 6N-able discloses CVE-2026-86218, a separate zero-day, pre-auth RCE (CVSS 10.0), reported by an independent third-party researcher. Hotfix 4 (2026.3.1.14) released, superseding HF3. N-able states the flaw "has been observed being exploited in the wild" in direct customer notices, while release notes state exploitation in production is unconfirmed.
Sep 6–7CISA adds CVE-2026-86218 to the KEV catalog; federal remediation deadline set for September 11, 2026.
Sep 7Widespread security media coverage (BleepingComputer, The Hacker News, Help Net Security).

Four hotfixes in five weeks across three distinct vulnerability chains (CVE-2026-18556/18577 in August; CVE-2026-86206/86207 and CVE-2026-86218 in September) make N-central one of the most heavily targeted MSP platforms of 2026.


Affected Products & Versions

  • Product: N-able N-central
  • Deployment types: On-premises (self-hosted) and Hosted (NCOD)
  • Affected: All builds prior to 2026.3.1.14
  • Not affected / remediated: 2026.3.1.14 and later (Hotfix 4). Hosted/NCOD instances were patched by N-able directly — no customer action required for NCOD.
  • Underlying OS: N-central appliances run a custom AlmaLinux 9 distribution, and — notably — rarely have EDR/AV deployed on the appliance itself because it is treated as a sealed appliance. This materially increases dwell-time risk.

Am I affected?

root@kitploit:~
N-central version < 2026.3.1.14   → VULNERABLE, patch immediately
N-central version = 2026.3.1.14+  → Patched against CVE-2026-86218

Check your build number in the N-central admin console under Administration → Software Updates, or via your appliance's version banner.


How the Exploit Works

CVE-2026-86218 is classified under CWE-96 (Improper Neutralization of Directives in Statically Saved Code / "static code injection"). In plain terms:

  1. An unauthenticated attacker sends a crafted HTTP request to a public-facing N-central endpoint.
  2. Attacker-controlled input reaches a code path where it is written into a statically interpreted/executed artifact (e.g., a script, template, or configuration object) on the server.
  3. That artifact is subsequently executed by the N-central application, running arbitrary OS commands under the privileges of the N-central server process.
  4. No authentication, prior account, or user interaction is required — only network reachability to the N-central web interface.

N-able has not published full public root-cause/technical exploitation details, which is standard practice for an actively exploited zero-day. This repository will be updated as more technical detail becomes public.

Related tradecraft observed in the same campaign window

While full technical details of CVE-2026-86218 specifically remain non-public, Huntress documented concrete attacker tradecraft against N-central during the same multi-week campaign (some tied to the related CVE-2026-86206/CVE-2026-86207 auth-bypass chain disclosed one day earlier). Defenders should hunt for all of the following regardless of which specific CVE was the entry vector, since they represent the observed post-exploitation pattern against N-central in this campaign:

  • Reconnaissance: Requests to /remoteControlAction.do?method=getPierDetails probing specific appliance IDs prior to exploitation.
  • Account manipulation: Newly created or modified user accounts with .invalid (or similar) appended to otherwise legitimate-looking email addresses.
  • API abuse: URL-encoded path traversal / endpoint anomalies in appliance API logs (e.g., encoded %2F sequences reaching internal routes).
  • Take Control abuse: Sessions from the default MSP Support account originating from unrecognized IPs, followed by Windows Event IDs 4102, 8192, 8193 on managed endpoints.
  • Persistence: Cloudflare Tunnel deployment for covert C2/backdoor access, sometimes disguised as a scheduled task or service named Cloudflared, or a dropped binary named svchost.exe in a user's Documents folder.

Indicators of Compromise (IOCs)

Machine-readable versions are in iocs/ as JSON, CSV, and flat .txt (for direct firewall blocklist / grep ingestion).

Important: Most published network IOCs below (IP addresses, domains) originate from the August 2026 campaign (CVE-2026-18556 / CVE-2026-18577) and the September 5 campaign (CVE-2026-86206 / CVE-2026-86207), collected and published by N-able and Huntress. As of this writing, no CVE-2026-86218-specific network IOCs (IPs/domains) have been publicly attributed — N-able's advisory for CVE-2026-86218 contains no IOCs, and Huntress states it has not reproduced or attributed a specific intrusion to this CVE. They are included here because (a) they represent the same threat activity cluster targeting N-central over the same weeks, (b) infrastructure reuse across waves is common, and (c) historical IOC coverage remains valuable for retrospective hunting. Treat them as high-value hunting leads, not proof of CVE-2026-86218 exploitation specifically. This repo will be updated immediately if/when CVE-2026-86218-specific network IOCs are published.

Malicious IPv4 Addresses

IP AddressDescriptionSource Wave
173.249.252.200Known malicious IP (Mullvad/NordVPN exit)Aug 1 advisory
87.249.138.34NordVPN exit node, attributed trafficAug 1 advisory
37.19.210.32Mullvad VPN exit; prior history of brute-force/spam abuseAug 1 advisory
68.235.46.214Known malicious IPAug 1 advisory
37.153.90.88Known malicious IPAug 2 advisory
92.118.112.181Known malicious IPAug 2 advisory
173.249.252.176Known malicious IPAug 6 advisory
185.156.46.150Known malicious IPAug 6 advisory
23.234.94.43Known malicious IPAug 6 advisory
68.235.46.235Known malicious IPAug 6 advisory
23.234.100.105Intruder IPv4 (Tzulo VPN)Sep 5 update
23.234.97.68Intruder IPv4 (Tzulo VPN)Sep 5 update

Known Malicious Domains

DomainDescription
mousears.synology.meAttacker-associated dynamic DNS domain
wagoosh.direct.quickconnect.toAttacker-associated dynamic DNS domain
who-ripped-one.direct.quickconnect.toAttacker-associated dynamic DNS domain

Other Indicators

IndicatorTypeDescription
5568cd69c754b392121f1dbb8f900fdaCloudflare tunnel account tagMalicious Cloudflare Tunnel account tag used for covert persistence
MSP SupportAccount nameDefault legitimate N-central Take Control account name — watch for logins from unexpected IPs, not the name itself
*.invalid suffix on email/account namesBehavioral patternAttacker-created accounts appending .invalid (or similar) to spoof legitimate N-able addresses
svchost.exe in user's Documents folderFile artifactMisnamed dropped binary flagged by N-able (masquerading as a Windows system process, but in the wrong location)
Service name CloudflaredWindows serviceUnauthorized Cloudflare Tunnel service registered for persistence
/remoteControlAction.do?method=getPierDetailsHTTP endpointPre-exploitation reconnaissance endpoint probed by attackers
URL-encoded %2F in API pathsLog patternEndpoint/path anomaly indicating possible API manipulation

Log / Artifact Locations to Hunt

PathPlatformNotes
envoy_proxy_HTTPS.logN-central appliance (AlmaLinux 9)Primary API/HTTPS access log
syslog (ncentraldms)N-central applianceSystem-level service log
ui_access_control.log (or equivalent)N-central web applicationUI/remote-access session log
C:\ProgramData\GetSupportService_N-Central\Logs\Windows managed endpointsTake Control breadcrumb directory
BASupSrvc_*.log.gz, BASupTSHelper_*Windows managed endpointsTake Control session log files — presence alone is not proof of compromise; correlate with IOC IPs and unexpected viewer identity
Windows Application Event Log IDs 4102, 8192, 8193Windows managed endpointsTake Control session start/end events

Repository Structure

root@kitploit:~
CVE-2026-86218-N-central-IOC-Toolkit/
├── README.md                          # You are here
├── LICENSE
├── CHANGELOG.md
├── iocs/
│   ├── ioc-list.json                  # Master machine-readable IOC set
│   ├── ioc-list.csv                   # Spreadsheet / SIEM-import friendly
│   ├── malicious-ips.txt              # Flat IP list for firewall/blocklist ingestion
│   └── malicious-domains.txt          # Flat domain list for DNS sinkhole/blocklist ingestion
├── scripts/
│   ├── cve_2026_86218_ioc_scanner.py  # Main Python log-hunting / IOC scanner
│   └── requirements.txt
├── detection/
│   ├── sigma/
│   │   ├── ncentral_invalid_account_creation.yml
│   │   ├── ncentral_ioc_ip_connection.yml
│   │   ├── ncentral_getpierdetails_recon.yml
│   │   └── ncentral_cloudflared_persistence.yml
│   ├── splunk/
│   │   └── cve-2026-86218_spl_queries.spl
│   └── elastic/
│       └── cve-2026-86218_kql_queries.md
├── docs/
│   ├── TIMELINE.md
│   ├── REMEDIATION.md
│   ├── INCIDENT_RESPONSE_CHECKLIST.md
│   ├── FAQ.md
│   └── REFERENCES.md
└── .github/
    └── workflows/
        └── validate-iocs.yml           # CI: lints IOC JSON/CSV on every push

Quick Start — Run the IOC Scanner

The scanner (scripts/cve_2026_86218_ioc_scanner.py) is a read-only, offline Python 3 tool. It never contacts your N-central server directly — you export or copy the relevant log files locally, then point the scanner at them. It:

  • Matches log lines against all known malicious IPs/domains
  • Flags .invalid-style account-name anomalies
  • Flags getPierDetails reconnaissance requests
  • Flags URL-encoded %2F API path anomalies
  • Flags the known malicious Cloudflare tunnel account tag
  • Produces a JSON and CSV findings report with severity and matched indicator

1. Clone the repo

root@kitploit:~
git clone https://github.com/jithinkrishnanrs/CVE-2026-86218-N-central-IOC-Toolkit.git
cd CVE-2026-86218-N-central-IOC-Toolkit
pip install -r scripts/requirements.txt

2. Point it at your logs

root@kitploit:~
python3 scripts/cve_2026_86218_ioc_scanner.py \
  --logs /path/to/ncentral/logs \
  --ioc-file iocs/ioc-list.json \
  --output findings_report

This scans envoy_proxy_HTTPS.log, syslog, ui_access_control.log, and any other .log/.log.gz/.txt files under the target directory (recursively), including gzip-compressed log files.

3. Review the output

root@kitploit:~
findings_report.json     # full machine-readable findings
findings_report.csv      # spreadsheet-friendly summary

Each finding includes: matched indicator, indicator type, severity, source file, line number, and (when parseable) timestamp.

Example

root@kitploit:~
python3 scripts/cve_2026_86218_ioc_scanner.py \
  --logs ./sample_logs \
  --ioc-file iocs/ioc-list.json \
  --output ./report \
  --verbose

Full CLI reference: run python3 scripts/cve_2026_86218_ioc_scanner.py --help.


Detection Content (Sigma / Splunk / Elastic)

Ready-to-import detection rules live under detection/:

  • Sigma (detection/sigma/*.yml) — vendor-agnostic; convert with sigma-cli to Splunk, Elastic, Sentinel, QRadar, etc.
  • Splunk SPL (detection/splunk/cve-2026-86218_spl_queries.spl) — ready-to-run searches
  • Elastic / KQL (detection/elastic/cve-2026-86218_kql_queries.md) — ready-to-run queries for Kibana / Elastic Security

Covered detections:

  1. IOC IP/domain connections to/from N-central infrastructure
  2. .invalid-suffixed account creation/modification
  3. getPierDetails reconnaissance probing
  4. Unauthorized Cloudflared service / tunnel persistence
  5. Anomalous Windows Take Control session activity (Event IDs 4102/8192/8193) from non-standard source IPs

Remediation & Patch Guidance

Patch immediately — this is the primary and only complete fix.

  1. On-premises N-central: Upgrade to N-central 2026.3 Hotfix 4 (build 2026.3.1.14). If you already applied HF3 (2026.3.1.13), you are still vulnerable to CVE-2026-86218 and must upgrade again to HF4.
  2. Hosted N-central (NCOD): No customer action required — N-able has already patched hosted instances.
  3. Cannot patch immediately? Take the appliance offline or fully restrict inbound access (IP allowlist / VPN-only) until you can patch. Do not leave an unpatched, internet-exposed N-central server running.
  4. After patching: Do not assume you're clean — hunt using this repo's IOC scanner and detection rules before considering the incident closed.

Full step-by-step guidance: docs/REMEDIATION.md.


Incident Response Checklist

A condensed version — full checklist in docs/INCIDENT_RESPONSE_CHECKLIST.md:

  • Confirm current N-central build number; patch to 2026.3.1.14 (HF4)
  • Restrict N-central console access to VPN/allowlisted IPs; enforce MFA on all accounts
  • Run scripts/cve_2026_86218_ioc_scanner.py against envoy_proxy_HTTPS.log, syslog, and UI access logs
  • Audit all N-central user accounts for .invalid-style anomalies, unexpected admins, or loosened permissions
  • Review Take Control / remote-control session logs for unrecognized viewer IPs, especially against domain controllers
  • Check managed Windows endpoints for C:\ProgramData\GetSupportService_N-Central\Logs\ artifacts correlated with IOC IPs
  • Hunt for Cloudflared services/scheduled tasks and misplaced svchost.exe in user Documents folders
  • Cross-reference any hits against Windows Event IDs 4102, 8192, 8193
  • If compromise is confirmed: rotate all N-central credentials, API keys, and stored managed-device credentials; assume downstream client environments may be affected and scope accordingly
  • Report confirmed compromise to N-able support and, where applicable, to CISA / your national CERT

Detection Notes / Important Caveats

  • N-able's own advisory and release notes for CVE-2026-86218 contain no published IOCs at time of writing.
  • Huntress explicitly states it has not reproduced CVE-2026-86218 and has not observed exploitation compromises definitively attributable to this specific CVE in its telemetry — a prior compromise it investigated could not be attributed to a specific CVE because appliance logs had rotated before analysis began.
  • N-able's incident/customer notices describe exploitation "observed in the wild," while N-able's public release notes state there is no confirmation of exploitation in production environments. Both statements are reflected here for transparency — see References for primary sources.
  • Absence of IOC matches does not mean you are not compromised. Given rotated/limited default logging on the appliance, a clean scan should be treated as inconclusive, not as proof of no compromise. Patch regardless.

Frequently Asked Questions

See docs/FAQ.md for the full list. Highlights:

Is there a public PoC/exploit for CVE-2026-86218? Not in this repository, and none has been responsibly published by the reporting researcher or N-able as of this writing. This repo is detection/IOC-only by design.

Is CVE-2026-86218 the same as CVE-2026-86206/86207? No. CVE-2026-86206/86207 (disclosed Sep 5) is a separate authentication-bypass chain enabling unauthorized admin account creation. CVE-2026-86218 (disclosed Sep 6) is a distinct, unrelated pre-auth static code injection RCE. They were disclosed one day apart and both required urgent hotfixes, which has caused confusion in the community.

Does patching to HF4 also fix the August/CVE-2026-18556/18577 and CVE-2026-86206/86207 issues? Yes — HF4 supersedes HF3, HF2, and HF1, so a fully patched 2026.3.1.14 appliance addresses all five 2026 N-central CVEs disclosed to date.

My N-central server has no EDR — is that normal? Yes, and it's a known risk factor. N-central appliances run a custom AlmaLinux 9 build and are commonly treated as a sealed appliance without endpoint security tooling installed on the appliance itself. Compensate with strict network segmentation, log forwarding to a SIEM, and external monitoring.


References & Credits

  • N-able Security Advisory — CVE-2026-86218: https://me.n-able.com/s/security-advisory/aArVy0000002Ld3KAE/cve202686218-preauthentication-remote-code-execution
  • N-able Status / Hotfix 4 Release Notes: https://status.n-able.com/2026/09/06/n-central-2026-3-hotfix-4-cve-2026-86218/
  • N-able Active Incident Page: https://uptime.n-able.com/event/201814/
  • Huntress — "Rapid Response: Critical N-able N-central Vulnerability and Active Exploitation": https://www.huntress.com/blog/n-able-vulnerability-exploitation
  • The Hacker News — "N-able N-central Pre-Auth RCE Flaw Exploited in the Wild": https://thehackernews.com/2026/09/n-able-n-central-pre-auth-rce-flaw.html
  • The Hacker News — "N-able Issues Fourth N-central Hotfix in Five Weeks": https://thehackernews.com/2026/09/n-able-issues-fourth-n-central-hotfix.html
  • Help Net Security — "N-able patches critical N-central zero-day exploited in the wild": https://www.helpnetsecurity.com/2026/09/07/n-able-n-central-hotfix-cve-2026-86218/
  • OpenCVE — CVE-2026-86218 enrichment: https://app.opencve.io/cve/CVE-2026-86218
  • VulDB — CVE-2026-86218 in N-central: https://vuldb.com/cve/CVE-2026-86218
  • Arctic Wolf — "Active Exploitation of N-able N-central": https://arcticwolf.com/resources/blog/cve-2026-86218/
  • Ionix Threat Center — CVE-2026-86218: https://www.ionix.io/threat-center/cve-2026-86218/
  • CISA Known Exploited Vulnerabilities (KEV) Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  • MITRE CVE Record: https://www.cve.org/CVERecord?id=CVE-2026-86218

All IOC data and tradecraft descriptions in this repository are sourced and paraphrased from the above publicly available advisories. This repo adds no original vulnerability research — it exists purely to aggregate, structure, and operationalize public information for defenders. Full credit for original discovery, disclosure, and analysis belongs to N-able and Huntress Labs.


Disclaimer

This repository is provided for defensive security, threat-hunting, and incident-response purposes only.

  • It contains no exploit code, no proof-of-concept, and no weaponized payloads.
  • IOCs (IPs, domains, hashes, tags) may become stale, be reused by unrelated actors, or be reassigned (e.g., VPN exit nodes) over time — always corroborate with additional context before taking action such as blocking or termination.
  • The maintainer(s) of this repository are not affiliated with N-able, Huntress Labs, CISA, or any organization referenced herein.
  • Use of the included scanner against systems you do not own or have explicit authorization to test/monitor may violate applicable law. You are solely responsible for lawful use.
  • Information here is current as of the last commit date and may not reflect the latest advisory updates — always cross-check against N-able's official advisory before making remediation decisions.

Contributing

Pull requests are welcome — especially:

  • Newly published IOCs for CVE-2026-86218 specifically (please cite a primary source)
  • Additional Sigma/Splunk/Elastic/Sentinel/QRadar detection content
  • Scanner improvements (new log formats, performance, false-positive tuning)
  • Corrections to timeline/technical details as N-able publishes more information

See CONTRIBUTING guidance in docs/FAQ.md or just open a PR/issue.

License

Released under the MIT License. IOC data itself is aggregated from public vendor/researcher advisories (see References) and is provided as-is with no warranty of accuracy or completeness.


Keywords

CVE-2026-86218 N-able N-central RMM security pre-auth RCE remote code execution static code injection CWE-96 CISA KEV MSP security IOC list indicators of compromise threat hunting incident response Sigma rules Splunk detection Elastic detection vulnerability scanner N-central hotfix zero-day RMM exploit supply chain attack MSP N-central patch Huntress Labs Take Control abuse Cloudflare tunnel persistence

Download Tool