Back to advisories

N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw

N-able N-central RMM platform contains a critical unauthenticated RCE vulnerability (CVE-2026-86218, CVSS 10.0) affecting all builds before 2026.3.1.14. While N-able denies confirmed exploitation, incident reports indicate active wild exploitation. Any organization running N-central is at immediate risk of full system compromise.

CRITICALAdvisorySep 07, 2026
Action required
Immediately patch N-central to build 2026.3.1.14 or later. If patching is not immediately possible, isolate N-central instances from untrusted networks and enable detailed logging for authentication attempts and process execution.
Affected products
N-centralN-able