Security advisories

HotFix for N-able N-central CVE-2026-86218

September 8, 2026

3 MINS READ

The Threat

On September 6th, 2026, N-able disclosed and patched three critical and high-severity vulnerabilities in the N-central RMM platform, with one flaw confirmed exploited in the wild. The exploited vulnerability is tracked as CVE-2026-86218 (CVSS: 10). The vulnerability is a pre-authentication Remote Code Execution (RCE) flaw that would allow a remote and unauthenticated threat actor to execute code on vulnerable assets. N-able and security researchers have confirmed real-world exploitation.

As exploitation is ongoing, it is critical that impacted organizations apply the N-able hotfix immediately.

What We're Doing About It

What You Should Do About It

Additional Information

According to N-able, independent security researchers have reported attacks targeting CVE-2026-86218. Huntress has confirmed attacks exploiting vulnerabilities in fully patched N-able N-central instances but did not specify which vulnerability was exploited in the attacks.

The two other vulnerabilities addressed in this hotfix are:

These two vulnerabilities could be chained together, enabling an unauthenticated remote attacker to reach privileged internal SOAP/API endpoints and create a new System Administrator account on the N-central server. Exploitation of these vulnerabilities has not been positively confirmed at the time of writing, but technical details were disclosed. The release of technical information or Proof-of-Concept (PoC) exploit code lowers the barriers for threat actors to develop their own exploits and increases the likelihood of real-world attacks.

This is the fourth hotfix that N-able has released since August 2nd, 2026. The repeated targeting of new vulnerabilities indicates a high level of attacker interest. Organizations must apply the hotfix immediately and are encouraged to monitor N-able for additional releases.

References:

[1] https://uptime.n-able.com/event/201814/
[2] https://nvd.nist.gov/vuln/detail/cve-2026-86218
[3] https://www.huntress.com/blog/n-able-vulnerability-exploitation
[4] https://nvd.nist.gov/vuln/detail/cve-2026-86206
[5] https://nvd.nist.gov/vuln/detail/cve-2026-86207
[6] https://www.rapid7.com/blog/post/ve-cve-2026-86206-cve-2026-86207-n-able-n-central-authentication-bypass-fixed/

Back to Security Advisories

Speak With A Security Expert Now

TALK TO AN EXPERT
View Most Recent Advisories