← Back to overview

N-able has released its fourth hotfix in five weeks for its N-central remote monitoring and management (RMM) platform to address an unauthenticated remote code execution (RCE) vulnerability. Every on-premises N-central build below version 2026.3.1.14 is affected, including those updated to Hotfix 3 just a day prior. The vulnerability is serious enough that N-able's incident notice states it has been exploited in the wild, although the release notes describe exploitation as unconfirmed. The rapid succession of hotfixes indicates the complexity and severity of fully remediating the underlying flaw. RMM platforms like N-central are high-value targets as they provide broad access to managed endpoints across many organizations. Administrators are urged to apply Hotfix 4 immediately to all affected on-premises deployments.

Technical details

CVE-2026-86218 is a maximum-severity (CVSS 4.0 score: 10.0) pre-authentication remote code execution vulnerability in N-able N-central, classified as a static code injection weakness (CWE-96). It affects all N-central on-premises builds prior to 2026.3.1.14, including those already patched to Hotfix 3 (2026.3.1.13). This is the fourth hotfix in five weeks for the 2026.3 line. N-able's communications are contradictory: release notes and status post claim no confirmed exploitation in production environments, while the incident notice states the flaw 'has been observed being exploited in the wild.' Huntress investigated a customer compromise starting September 4 on a fully patched N-central production environment (build 2026.3.1.10) and reproduced a proof-of-concept exploit chain, but could not definitively link it to CVE-2026-86218 due to log rotation. Prior hotfixes addressed: Hotfix 1 (CVE-2026-18577, authentication bypass/account takeover, confirmed exploited), Hotfix 2 (additional hardening for related attack path), Hotfix 3 (CVE-2026-86206 - unauthorized access to internal APIs via access control filter, CVSS 6.9 Medium; CVE-2026-86207 - authentication bypass in internal-only APIs, CVSS 7.7 High). In the July 31 intrusion, attackers used authentication bypass to gain admin access to N-central servers, then used the platform's Take Control feature to reach managed endpoints and register Cloudflare tunnel services on those devices for persistent access. This is the second consecutive summer with in-the-wild attacks on N-central (also occurred August 2025 with CVE-2025-8875 and CVE-2025-8876).

Mitigation steps

1. Immediately upgrade all on-premises N-central installations to build 2026.3.1.14 (Hotfix 4) - this applies even to servers already updated to Hotfix 3 (2026.3.1.13). 2. Hosted N-central (NCOD) instances have already been patched by N-able; no action required for those. 3. Agent upgrades are not required to be protected from CVE-2026-86218. 4. Audit N-central user accounts for unexpected or unauthorized users. 5. Restrict inbound access to the N-central console using IP allowlisting or a VPN. 6. If the N-central server is still reachable from the internet and the hotfix cannot be applied immediately, consider taking the server offline until patched. 7. Review managed endpoints for unexpected Cloudflare tunnel services, which may indicate persistent attacker access established via the Take Control feature. 8. Monitor for CISA Known Exploited Vulnerabilities catalog updates related to N-central CVEs.

Affected products

  • 2026.3.1.10
  • 2026.3.1.13) (on-premises)
  • N-able N-central (on-premises) - all builds before 2026.3.1.14
  • N-able N-central 2025.4 (on-premises)
  • N-able N-central 2026.1 (on-premises)
  • N-able N-central 2026.2 (on-premises)
  • N-able N-central 2026.3 (on-premises)
  • N-able N-central 2026.3.1 hotfixes (2026.3.1.7

Related CVE's

  • CVE-2025-8875
  • CVE-2025-8876
  • CVE-2026-18556
  • CVE-2026-18577
  • CVE-2026-86206
  • CVE-2026-86207
  • CVE-2026-86218

Categories

  • Enterprise Applications
  • Identity & Access
  • Security Tools
  • Zero-Day Vulnerabilities