Managed IT software provider N-able has released a new hotfix that includes a patch for a critical remote code execution (RCE) vulnerability.
CVE-2026-86218 is a critical pre-authentication RCE flaw in N-central, N-able’s remote monitoring and management platform. It was disclosed by the software provider on September 6 and was allocated a maximum-severity rating (CVSS) of 10.
The vulnerability affects N-central versions before 2026.3.1.14 and can allow an unauthenticated attacker to execute code on the N-central server.
N-able has not publicly disclosed the affected component or exploitation method. It said it has found no evidence that CVE-2026-86218 has been exploited in production environments.
Meanwhile, the software provider released a patch for the vulnerability in its N-central 2026.3 Hotfix 4 , which brings the build to 2026.3.1.14.
This is the latest of five vulnerabilities affecting N-able products in a few weeks.
CVE-2026-18556 and CVE-2026-18577 are high-severity authentication bypasses that were found to be exploited earlier in 2026 – and added to the US Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities (KEV) catalog in August.
Patches for those two vulnerabilities were included in N-able’s HF1 and HF2 hotfixes, published on August 2 and 6.
CVE-2026-86207 is a high-severity authentication bypass affecting internal only APIs and CVE-2026-86206 is a high-severity access-control filter bypass exposing internal APIs. They were both patched in N-able’s HF3 hotfix on September 5.
Image credits: Cristi Dangeorge / Shutterstock.com
The Most Exploited Vulnerabilities by State Actors, and the Easy Fix News Feature 15 May 2020
The Most Exploited Vulnerabilities by State Actors, and the Easy Fix
New Year, New Operating System Opinion 30 January 2020
New Year, New Operating System
How Forgotten Legacy Systems Could Be Your Downfall Opinion 18 April 2019
How Forgotten Legacy Systems Could Be Your Downfall
CISA Warns of Six Exploited Flaws in Microsoft, Linux, Red Hat and Citrix Products News 27 August 2026
CISA Warns of Six Exploited Flaws in Microsoft, Linux, Red Hat and Citrix Products
NIST Seeks Public Input on AI-Ready NVD Modernization News 12 August 2026
NIST Seeks Public Input on AI-Ready NVD Modernization
What’s Hot on Infosecurity Magazine?
FBI Probes Possible Breach of 153 Million Driver’s Licenses
US and Canadian Court Records Breached Following Thomson Reuters Incident
Pegasus Zero-Click Exploit Infects Serbian Student Activist's iPhone
CREST Onboards First Cohort for AI-Enabled Pentesting Accreditation
FulcrumSec Claims Responsibility for Manchester Airport Group Breach
65% of Enterprises Have Seen AI Agents Act Out of Scope
CREST Onboards First Cohort for AI-Enabled Pentesting Accreditation
Attackers Steal METR API Key and Burn $600,000 in AI Credits
New CREST AI Standards to Deliver AI-Enabled Pentesting Accreditation
Hiring for the AI Era: A New Challenge for CISOs
How Industry Coalitions Are Rallying to Secure Open Source Software for the AI Era
65% of Enterprises Have Seen AI Agents Act Out of Scope
Understanding Frontier AI Defense: What Cyber and IT Leads Need to Know
Same Front Door, New Visitors: Securing Humans and AI Agents at the Browser
Human Risk in Cybersecurity: Protecting Your Organization Beyond Technology
Predicting and Prioritizing Cyber Attacks Using Threat Intelligence
Financial Services Cyber Resilience: Stress Testing Third Parties Before Attackers Do
Behind the Curtain of Microsoft 365 Cybersecurity: Lessons from Overlooked Resilience Gaps
How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies
Researchers Claim First Fully Agentic Ransomware: JadePuffer
AI is Already Powering Cyber-Attacks. Can it Power Cyber Defense?
Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses
How World Cup Password Trends Can Increase Active Directory Risk
New CISA Guide Helps Agencies Adopt SASE For Zero Trust
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
