Back to Feed
VulnerabilitiesSep 7, 2026

N-able patches max severity N-central flaw amid ongoing attacks

N-able releases emergency patch for critical RCE flaw in N-central RMM platform amid ongoing attacks.

Summary

N-able has issued an emergency hotfix for a critical remote code execution (RCE) vulnerability (CVE-2026-86218) in its N-central RMM platform. The flaw allows unauthenticated attackers to execute malicious code on exposed instances. Cybersecurity firm Huntress flagged it as a potential zero-day and noted that two other high-severity authentication bypass vulnerabilities (CVE-2026-86206 and CVE-2026-86207) were also patched, with evidence suggesting exploitation in a customer environment.

Full text

N-able patches max severity N-central flaw amid ongoing attacks By Sergiu Gatlan September 7, 2026 02:17 AM 0 N-able has released an emergency hotfix for a maximum-severity remote code execution (RCE) flaw affecting its N-central remote monitoring and management (RMM) platform. IT departments and managed service providers (MSPs) use the N-central platform to monitor, manage, and maintain client networks and devices from a centralized web-based console. Tracked as CVE-2026-86218, this RCE vulnerability allows threat actors without privileges to execute malicious code on unpatched N-central instances exposed online in low-complexity attacks. N-able addressed the flaw on Saturday by releasing N-central 2026.3 Hotfix 4 and urging customers to patch as soon as possible. "At this time, we have no confirmations that this vulnerability has been exploited in production environments, but unpatched systems remain at risk," the company said. "Customers running on-premises N-central deployments should upgrade to N-central 2026.3 HF4 immediately to protect their environment." Internet security nonprofit Shadowserver Foundation now tracks nearly 1,500 N-central servers exposed online, most of them located in the United States and Europe. Internet-exposed N-able N-central instances (Shadowserver) Evidence of active exploitation​ While N-able has yet to confirm that the CVE-2026-86218 flaw is being targeted, cybersecurity company Huntress has flagged it as a potential zero-day, along with two high-severity vulnerabilities (tracked as CVE-2026-86206 and CVE-2026-86207, and also patched over the weekend) that can allow attackers to bypass authentication and gain full access to the vulnerable N-central platform. "In our 9/5/26 update [..], we had said we could not rule out whether the two previous vulnerabilities released (CVE-2026-86206 and CVE-2026-86207) were the ones that were exploited in the instance seen in the patched production environment of one of our customers," Huntress said. "Because logs on the compromised N-central server had already rotated, we are also unable to say whether this new CVE was the vulnerability exploited in that case." "On-premises N-central users must apply HF4 immediately, as systems running HF3 remain vulnerable to this newly disclosed flaw," Huntress warned. One year ago, N-able released security updates for two N-central vulnerabilities (CVE-2025-8875 and CVE-2025-8876) that attackers were exploiting in the wild. Days later, Shadowserver found that 880 N-central servers were still vulnerable to attacks exploiting the two security flaws even after CISA ordered federal agencies to patch their systems within a week and urged all security teams to also prioritize securing their systems against ongoing attacks. Once attackers have valid credentials, only 37% of their actions are blocked Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report Related Articles: SonicWall warns of actively exploited SMA1000 zero-day flawsCISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flawsCritical Elementor Pro flaw exploited to take over WordPress sitesHackers exploit Sangoma Switchvox flaw to deploy reverse shellsCritical Langflow flaw exploited to steal OpenAI and AWS keys

Indicators of Compromise

  • cve — CVE-2026-86218
  • cve — CVE-2026-86206
  • cve — CVE-2026-86207
  • cve — CVE-2025-8875
  • cve — CVE-2025-8876

Entities

N-central (product)N-able (vendor)RMM (technology)N-central 2026.3 Hotfix 4 (product)