N-able shipped an emergency hotfix for a maximum-severity flaw in its N-central platform on September 6, 2026. The N-able N-central vulnerability, CVE-2026-86218, is a pre-auth remote code execution zero-day rated a perfect 10.0 CVSS. N-able’s incident notice says the flaw has been observed exploited in the wild.
- CVE: CVE-2026-86218
- CVSS: 10.0 (Critical · CVSSv4)
- Product: N-able N-central
- Affected: < 2026.3.1.14
- Impact: pre-authentication remote code execution
- Status: Exploited in the wild
- Patched in: 2026.3.1.14
- EPSS: 0.4% (30-day)
- Action: Update to 2026.3.1.14 now
Why this matters
N-central is a remote monitoring and management (RMM) platform used by managed service providers. So one compromised server can reach every downstream endpoint it manages. An attacker could run scripts, push tools, and open remote sessions across many networks at once. The pre-auth nature removes the last hurdle, since no login is required.
The scale of exposure is large. The Shadowserver Foundation counted nearly 1,500 internet-facing N-central servers, mostly in the US and Europe. Each unpatched, exposed console is a high-value target.
The RMM angle raises the stakes further. A single MSP often manages hundreds of client networks from one console. Therefore, one breach can cascade into a supply-chain event. N-able also has recent history here, since CVE-2025-8875 and CVE-2025-8876 were exploited earlier and later landed on CISA’s Known Exploited Vulnerabilities catalog.
How the attack works
The headline flaw, CVE-2026-86218, allows pre-authenticated remote code execution. N-able describes it plainly: “N-central is vulnerable to a pre-auth remote code execution.” Because it needs no credentials, a network-accessible attacker can run code on the server directly. N-able has not published root-cause details, which limits public mechanism analysis.
A separate auth-bypass chain
Two other flaws were patched the same weekend. CVE-2026-86206 (CVSS 6.9) is an internal API access-control flaw. CVE-2026-86207 (CVSS 7.7) is an authentication bypass in internal APIs. Chained, they let an attacker create unauthorized administrative accounts. Huntress built a working proof-of-concept for this chain against the latest build.
Exploitation status
The exploitation status is nuanced, so read it carefully. N-able’s Active Incident post states this N-able N-central vulnerability “has been observed being exploited in the wild.” A company engineer also called it a zero-day. However, N-able’s release notes strike a more cautious tone: “we have no confirmations that this vulnerability has been exploited in production environments, but unpatched systems remain at risk.”
Huntress adds field context. Its team investigated a compromised, fully patched customer environment on September 4. As Huntress reports, rotated logs meant they “cannot definitively confirm which specific exploit the threat actor used.” So a real intrusion happened, but the exact CVE remains unconfirmed.
Huntress also documented attacker tradecraft worth hunting for. Attackers created accounts by appending odd strings, such as .invalid, to known N-able email addresses. Before exploitation, they probed an internal reconnaissance endpoint to map the appliance. Huntress further worked with Cloudflare to disable attacker tunnels tied to a shared account token.
Affected versions
CVE-2026-86218 affects all N-central builds before 2026.3.1.14. Notably, Hotfix 3 remains vulnerable to it. The two access-control flaws affect versions before 2026.3 HF3. Hosted (NCOD) instances were patched by N-able automatically.
This flaw also caps a busy patch sequence. In August, N-able disclosed two earlier bugs, CVE-2026-18556 and CVE-2026-18577, and shipped hotfixes for them. HF3 then fixed the access-control pair, and HF4 closed the pre-auth RCE. As a result, verifying the exact build number matters more than usual.
Patch and mitigation steps
On-premises customers must upgrade to 2026.3 HF4, build 2026.3.1.14, at once. If you already applied HF3, you still need HF4 to close the RCE. Refer to N-able’s active incident notice for upgrade guidance. Verify the live server reports build 2026.3.1.14, since checking for “2026.3” alone is not enough.
After patching, hunt for signs of abuse. Audit user lists for anomalous accounts, especially emails ending in .invalid. Review appliance logs for API manipulation and unexpected admin creation. Finally, restrict all inbound access to the console through IP allowlisting or a VPN. If your server is broadly reachable, consider taking it offline until patched.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!