Critical N-able N-central Vulnerability Enables Remote Code Execution

Critical N-able N-central Vulnerability Enables Remote Code Execution

First seen 7 Sep 2026, 10:21 UTC GbhackersThehackernewsstatus.n-able.comdocumentation.n-able.comwww.cve.org 74.0

Article Content

Browse articles
ThreatCluster

N-able has issued a critical hotfix for a vulnerability (CVE-2026-86218) in its N-central platform that allows pre-authenticated remote code execution. This flaw affects all on-premises N-central builds prior to version 2026.3.1.14, including those recently updated to Hotfix 3. Although N-able has stated there are no confirmations of exploitation in production environments, they caution that unpatched systems remain at risk. The vulnerability was disclosed by a third party, and N-able's communications have conflicting statements regarding whether it has been exploited in the wild. Administrators are urged to upgrade immediately to mitigate potential risks. The hotfix was released on September 6, 2026, following the discovery of this critical flaw. N-able has advised restricting inbound access and monitoring user accounts for unexpected activity as interim measures.

Key Points: • CVE-2026-86218 allows pre-authenticated remote code execution on N-central servers. • All on-premises builds before version 2026.3.1.14 are affected and must be updated immediately. • N-able's communications show conflicting reports on whether the vulnerability has been exploited.

Ask AI about this cluster

Timeline

2025-08-13
CVE-2025-8876 added to CISA KEV
CISA flagged the vulnerability as actively exploited in the wild and added it to the Known Exploited Vulnerabilities catalog.
CISA KEV
2025-08-13
CVE-2025-8875 added to CISA KEV
CISA flagged the vulnerability as actively exploited in the wild and added it to the Known Exploited Vulnerabilities catalog.
CISA KEV
2026-08-01
CVE-2026-18556 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-02
CVE-2026-18577 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-05
CVE-2026-86206 and CVE-2026-86207 published
N-able disclosed two high-severity vulnerabilities that could allow unauthorized access to the N-central platform.
Article 3
2026-09-06
CVE-2026-86218 published
N-able released Hotfix 4 addressing a critical vulnerability allowing remote code execution.
Article 4
2026-09-07
Hotfix 4 released
N-able urges immediate upgrade to version 2026.3.1.14 for all on-premises deployments to mitigate risks.
Article 1