N-able Releases Hotfix for Severe RCE Vulnerability in N-central

Views: 34 views

491/69 Tuesday, September 8, 2026

N-able has released a hotfix to address a severe Remote Code Execution (RCE) vulnerability in N-central, a Remote Monitoring and Management (RMM) platform used by IT teams and Managed Service Providers (MSPs) to monitor, manage, and support customer networks and devices through a centralized web-based console. The vulnerability is tracked as CVE-2026-86218 and could allow an unauthenticated attacker to execute malicious code on unpatched N-central instances exposed to the internet. The attack complexity is considered low.

N-able fixed the vulnerability in N-central 2026.3 Hotfix 4 (HF4) and urged customers using on-premises N-central deployments to upgrade immediately to protect their environments. Although the company stated that it has not confirmed exploitation of CVE-2026-86218 in production environments, unpatched systems remain at risk. Meanwhile, the Shadowserver Foundation reported detecting nearly 1,500 internet-exposed N-central servers, mostly located in the United States and Europe.

Cybersecurity company Huntress stated that CVE-2026-86218 may be a zero-day vulnerability related to an attack observed in a customer’s production environment, although this could not be confirmed because logs on the compromised N-central server had already rotated. Huntress also referenced two other high-severity vulnerabilities, CVE-2026-86206 and CVE-2026-86207, which were previously fixed in N-central 2026.3 HF3 and could allow attackers to bypass authentication and gain full access to the N-central platform. Huntress warned that on-premises N-central users must install HF4 immediately, as systems updated only to HF3 remain vulnerable to CVE-2026-86218.

Source: https://www.bleepingcomputer.com/news/security/n-able-patches-max-severity-n-central-flaw-amid-ongoing-attacks/