N-able Releases Emergency Hotfix for Critical N-central RCE Vulnerability
N-able has released an emergency hotfix for a maximum-severity remote code execution (RCE) vulnerability affecting its N-central remote monitoring and management (RMM) platform.
IT departments and managed service providers (MSPs) use N-central to monitor, manage, and maintain client networks and devices through a centralized, web-based console.
Tracked as CVE-2026-86218, the RCE vulnerability allows an unauthenticated attacker to execute malicious code on an unpatched N-central server exposed to the internet. The flaw reportedly requires low attack complexity.
N-able addressed the vulnerability on Saturday by releasing N-central 2026.3 Hotfix 4 (HF4) and is urging customers to install the update immediately.
“At this time, there is no confirmation that this vulnerability has been exploited in production, but unpatched systems are still at risk,” N-able said.
“Customers running on-premises N-central deployments should upgrade to N-central 2026.3 HF4 immediately to protect their environments.”
Approximately 1,500 N-central servers exposed online
The Internet security nonprofit Shadowserver Foundation has begun tracking approximately 1,500 N-central servers accessible from the internet. Most of the exposed systems are located in the United States and Europe.

Previous N-central flaws may have been exploited
Although N-able has not confirmed that attackers have targeted CVE-2026-86218, cybersecurity firm Huntress recently identified two other high-severity vulnerabilities in N-central, tracked as CVE-2026-86206 and CVE-2026-86207.
The two vulnerabilities, patched over the weekend, could allow attackers to bypass authentication and gain complete access to vulnerable N-central platforms.
“Updated on 9/5/26 […] we could not rule out whether the two previous vulnerabilities, CVE-2026-86206 and CVE-2026-86207, were exploited in an instance observed in a patched production environment belonging to one of our customers,” Huntress said.
“We also do not know if this new CVE is the vulnerability exploited in that case, as the logs on the compromised N-central server were already being rotated.”
“On-premises N-central users should apply HF4 immediately, as systems running HF3 remain vulnerable to this newly disclosed flaw,” Huntress warned.
N-central users urged to patch immediately
A year ago, N-able released security updates for two N-central vulnerabilities, CVE-2025-8875 and CVE-2025-8876, which attackers were exploiting in the wild.
Days later, Shadowserver found that 880 N-central servers remained vulnerable to attacks targeting the two flaws. The discovery came after CISA directed federal agencies to patch their systems within a week and urged organizations to prioritize protecting systems from ongoing attacks.
The overall prevention score can hide what happens after initial access. If an attacker uses valid credentials, your defenses can drop sharply.
The Blue Report 2026 measures defense techniques by technology across 338 million simulations conducted in customer production environments.
Source: www.bleepingcomputer.com



