CVE Research
sekurity-team
InSEKurity of the Week (CW37/2026): N-able N-central Pre-Auth RCE via Struts BeanUtils Race (CVE-2026-86218)
Two concurrent multipart requests to an unauthenticated Struts action hand an attacker Jetty's live configuration, and from there a root-adjacent shell on the box that manages every endpoint an MSP touches. CVSS 10.0, exploited before disclosure, in CISA KEV on September 8 -- the fourth N-central hotfix in five weeks.
Exploit
01
