Back to advisories

N-able patches max severity N-central flaw amid ongoing attacks

N-able has released emergency patches for three vulnerabilities in N-central RMM, including a critical unauthenticated RCE (CVE-2026-86218) and two high-severity authentication bypasses. Evidence indicates active exploitation in customer environments. Any organization running N-central is at immediate risk of full system compromise.

CRITICALAdvisorySep 07, 2026
Action required
Immediately patch N-central to the latest version. For any instances you cannot patch within 24 hours, isolate them from production networks and implement network-based access controls. Scan all N-central logs for exploitation indicators and check for lateral movement from affected systems.
Affected products
N-centralN-ableN-central 2026.3 Hotfix 4