Critical N-able N-central Vulnerability Enables Remote Code Execution
Article Content
N-able has issued a critical hotfix for a vulnerability (CVE-2026-86218) in its N-central platform that allows pre-authenticated remote code execution. This flaw affects all on-premises N-central builds prior to version 2026.3.1.14, including those recently updated to Hotfix 3. Although N-able has stated there are no confirmations of exploitation in production environments, they caution that unpatched systems remain at risk. The vulnerability was disclosed by a third party, and N-able's communications have conflicting statements regarding whether it has been exploited in the wild. Administrators are urged to upgrade immediately to mitigate potential risks. The hotfix was released on September 6, 2026, following the discovery of this critical flaw. N-able has advised restricting inbound access and monitoring user accounts for unexpected activity as interim measures.
Key Points: • CVE-2026-86218 allows pre-authenticated remote code execution on N-central servers. • All on-premises builds before version 2026.3.1.14 are affected and must be updated immediately. • N-able's communications show conflicting reports on whether the vulnerability has been exploited.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.