Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-09-08 ยท updated: 2026-09-08 ยท tags: [incident, rmm, rce, zero-day, exploit, vulnerability] ยท confidence: high ยท affected_sectors: [technology] ยท au_impact: true

N-able Patches Max-Severity N-central Flaw Amid Ongoing Attacks

N-able released an emergency Hotfix 4 for a maximum-severity, unauthenticated remote code execution vulnerability (CVE-2026-86218) in its N-central remote monitoring and management (RMM) platform, which MSPs and IT teams use to manage client networks.

Attribute Detail
CVE CVE-2026-86218 (max-severity, unauthenticated RCE)
Fix 2026.3 Hotfix 4
Prior pair CVE-2026-86206 / CVE-2026-86207 (auth bypass)
Exposure ~1,500 internet-exposed N-central instances (Shadowserver)
Source BleepingComputer โ€” Tier 2/4

The vendor said it has no confirmation the flaw was exploited, but Huntress flagged it as a potential zero-day and could not rule it out in a customer incident because logs on the compromised N-central server had rotated. The fix arrives amid active attacks on the product. Organisations running on-premises N-central should apply 2026.3 Hotfix 4 immediately.

Related Pages

Source