Here are the main stories you missed last week. 1. N-able: CVE-2026-86218 CVSS 10.0 pre-auth RCE in N-central under active exploitation The headline: On September 8, 2026, CISA added CVE-2026-86218 to the Known Exploited Vulnerabilities catalog with a three-day federal patching deadline of September 11.