Critical Vulnerabilities in N-able N-central Expose Managed Services to Attacks

Critical Vulnerabilities in N-able N-central Expose Managed Services to Attacks

First seen 7 Sep 2026, 14:34 UTC Forkast.NewsTech.Yahoo 75.8

Article Content

Browse articles
ThreatCluster

Between August and September 2026, N-able N-central faced three waves of critical vulnerabilities, including CVE-2026-86218, a CVSS 10.0 pre-authentication remote code execution flaw. This vulnerability allows unauthenticated attackers to execute arbitrary code on the N-central server. It follows CVE-2026-86206 and CVE-2026-86207, which were part of an authentication bypass chain disclosed on September 5, enabling unauthorized administrative account creation. These vulnerabilities were preceded by CVE-2026-18577, an earlier authentication bypass added to the CISA Known Exploited Vulnerabilities catalog on August 3. Huntress reported active exploitation attempts across all three vulnerability waves, indicating a significant risk to managed service providers (MSPs) using N-central. N-able has released a patch for the latest RCE vulnerability, but on-premises customers must apply it manually. Administrators are advised to isolate affected servers and audit administrative accounts to mitigate risks.

Key Points: • N-able N-central has critical vulnerabilities with CVSS scores up to 10.0. • Active exploitation of these vulnerabilities has been confirmed by Huntress. • Immediate patching and server isolation are recommended for affected users.

Ask AI about this cluster

Timeline

2026-08-02
CVE-2026-18577 published
An authentication bypass vulnerability in N-central was disclosed, impacting multiple versions.
Tech.Yahoo
2026-08-03
CVE-2026-18577 added to CISA KEV
CISA included this vulnerability in its Known Exploited Vulnerabilities catalog due to active exploitation.
Tech.Yahoo
2026-09-05
CVE-2026-86206 and CVE-2026-86207 published
Two vulnerabilities in N-central were disclosed, allowing unauthorized account creation.
Tech.Yahoo
2026-09-06
CVE-2026-86218 published
A critical remote code execution vulnerability was disclosed, allowing unauthenticated code execution.
Tech.Yahoo