Back to advisories

N-able N-central Pre-Auth RCE Flaw Exploited in the Wild

CVE-2026-86218 is a critical pre-auth RCE in N-able N-central being actively exploited in the wild. Any organization running N-central is vulnerable to unauthenticated remote code execution. Federal agencies are mandated to patch by September 11, 2026.

CRITICALAdvisorySep 10, 2026
Action required
Immediately patch N-able N-central to the latest hotfix version. If you cannot patch today, isolate N-central instances from the internet until patched. Hunt for exploitation attempts in proxy and application logs targeting N-central endpoints.
Affected products
N-able N-centralN-ableN-central 2026.3 Hotfix 4N-central 2026.3 Hotfix 3N-central