Back to Feed
VulnerabilitiesSep 8, 2026

N-able Patches Critical Zero-Day in N-central

N-able patches critical zero-day RCE vulnerability in N-central endpoint management platform.

Summary

N-able has released an urgent fix for a critical zero-day vulnerability (CVE-2026-86218) in its N-central endpoint management platform, which allows for unauthenticated remote code execution. The vulnerability, discovered after patching two other flaws, has a CVSS score of 10/10 and has reportedly been exploited in the wild. Administrators are advised to apply the hotfix immediately and check for suspicious user accounts and scanning activity from the IP range 23.234.64.0/18.

Full text

IT software firm N-able has rolled out an urgent fix for an unauthenticated remote code execution (RCE) vulnerability in its N-central endpoint management platform that has been exploited as a zero-day. Tracked as CVE-2026-86218 (CVSS score of 10/10), the security defect was discovered after N-able patched two other flaws in N-central, namely CVE-2026-86206 and CVE-2026-86207 “This critical zero-day vulnerability, CVE-2026-86218, could allow pre-authenticated access to the N-central server if exploited,” N-able warns. While no action is required for N-central hosted environments, as the patches were deployed server-side, users of on-premises N-central instances should immediately apply the 2026.3 HF4 hotfix, the company says. “Review your logs for scanning activity. We’ve observed scans originating from the IP range 23.234.64.0/18 attempting to exploit this vulnerability. Check your logs for any connections from this range,” N-able also notes. Administrators are also advised to check their deployments for newly created user accounts they don’t recognize.Advertisement. Scroll to continue reading. “At this time, we have no confirmations that this vulnerability has been exploited in production environments, but unpatched systems remain at risk,” N-able says. The hotfix for the exploited zero-day supersedes the previously released patches for CVE-2026-86206 and CVE-2026-86207, two bugs that Huntress flagged as potentially chained together in the wild to bypass authentication and compromise N-central production environments. “However, due to limited historical logging available directly on the appliance, we cannot definitively confirm which specific exploit the threat actor used to achieve their compromise, nor can we rule out the use of alternative vulnerabilities,” Huntress said on Saturday. The cybersecurity firm observed attacks targeting N-central’s underlying API and appliance logs starting on September 4, 2026. Related: Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits Related: Adobe Commerce Zero-Day Exploited to Backdoor Online Stores Related: Modified ScreenConnect Clients Used in Worm-Like Campaign Related: Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire HPE Patches Critical RCE Vulnerabilities in AOS-CXSangoma Switchvox Vulnerability Exploited in the Wild12-Year-Old PostgreSQL Vulnerability Enables Database, Server TakeoverVMware Workstation and Fusion Updates Patch Critical VulnerabilityGoogle Patches 6th Chrome Zero-Day of 2026Manchester Airports Group Data on 8.8 Million People Leaked After Ransom RefusalHiddenLayer Raises $100 Million for AI Runtime Security153 Million Driver License Images Offered on Dark Web Latest News MikroTik Patches Critical Flaws Chained to Hack RoutersMathspace Data Breach Exposes Over 1 Million PeopleNightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day ExploitsNorth Korean Hackers Deploy New Linux Espionage ToolkitOpenAI Agents Hijack Another Victim WebsiteAdobe Commerce Zero-Day Exploited to Backdoor Online StoresModified ScreenConnect Clients Used in Worm-Like CampaignElementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the MoveFrank Verdecanna has been appointed Chief Financial Officer at Armadin.Keeper Security has named Jessica Krowel and Bill Grabner as SVPs of sales for North America.Skyhigh Security has named Anthony Palladino as Chief Operating Officer.More People On The MoveExpert Insights What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Hired for One Job, Judged on Another: The CISO’s Real Problem The skills that get a CISO hired are rarely the skills they are judged on later. Most security leaders are stuck in that gap. Closing it is the real job. (Sravish Sridhar) Flipboard Reddit Whatsapp Whatsapp Email

Indicators of Compromise

  • cve — CVE-2026-86218
  • cve — CVE-2026-86206
  • cve — CVE-2026-86207

Entities

N-central (product)N-able (vendor)