Critical RCE Vulnerability in N-able N-central Requires Immediate Patching

Critical RCE Vulnerability in N-able N-central Requires Immediate Patching

First seen 7 Sep 2026, 10:21 UTC GbhackersThehackernewsCybersecuritynewsstatus.n-able.comdocumentation.n-able.com+12 80.2

Article Content

Browse articles
ThreatCluster

N-able has released Hotfix 4 for its N-central platform to address CVE-2026-86218, a critical remote code execution (RCE) vulnerability rated CVSS 10.0. This flaw allows unauthenticated attackers to execute arbitrary code on N-central servers running versions prior to 2026.3.1.14. The vulnerability has been reported as being actively exploited in the wild, raising urgent concerns among managed service providers (MSPs) and IT teams. N-able's communications have been inconsistent regarding whether the vulnerability has been confirmed as exploited, with some reports indicating it has been observed in active attacks. Organizations using on-premises N-central installations are urged to upgrade immediately to mitigate risks. The situation is compounded by a series of vulnerabilities disclosed in recent weeks, including CVE-2026-86206 and CVE-2026-86207, which also require urgent attention. The ongoing threat landscape necessitates vigilant monitoring and prompt patching of affected systems.

Key Points: • CVE-2026-86218 is a critical RCE vulnerability with a CVSS score of 10.0. • N-able's N-central versions prior to 2026.3.1.14 are affected and should be patched immediately. • There are conflicting reports on whether the vulnerability has been actively exploited.

Ask AI about this cluster

Timeline

2025-08-13
CVE-2025-8875 added to CISA KEV
CISA flagged the vulnerability as actively exploited in the wild and added it to the Known Exploited Vulnerabilities catalog.
CISA KEV
2025-08-13
CVE-2025-8876 added to CISA KEV
CISA flagged the vulnerability as actively exploited in the wild and added it to the Known Exploited Vulnerabilities catalog.
CISA KEV
2026-08-01
CVE-2026-18556 published
A high-severity authentication bypass vulnerability was disclosed, later added to CISA KEV.
Infosecurity-Magazine
2026-08-02
CVE-2026-18577 published
A critical vulnerability was disclosed and added to CISA KEV due to active exploitation.
Infosecurity-Magazine
2026-09-05
CVE-2026-86206 and CVE-2026-86207 published
Two high-severity vulnerabilities were disclosed, requiring urgent patching.
Helpnetsecurity
2026-09-06
CVE-2026-86218 published
N-able released Hotfix 4 addressing the critical RCE vulnerability affecting N-central.
Servnetuk
2026-09-07
Active exploitation reported
Reports indicate that CVE-2026-86218 has been observed being exploited in the wild.
Digital.Nhs.Uk