Tech.Yahoo
Critical Vulnerabilities in N-able N-central Expose Managed Services to Attacks
Article Content
Between August and September 2026, N-able N-central faced three waves of critical vulnerabilities, including CVE-2026-86218, a CVSS 10.0 pre-authentication remote code execution flaw. This vulnerability allows unauthenticated attackers to execute arbitrary code on the N-central server. It follows CVE-2026-86206 and CVE-2026-86207, which were part of an authentication bypass chain disclosed on September 5, enabling unauthorized administrative account creation. These vulnerabilities were preceded by CVE-2026-18577, an earlier authentication bypass added to the CISA Known Exploited Vulnerabilities catalog on August 3. Huntress reported active exploitation attempts across all three vulnerability waves, indicating a significant risk to managed service providers (MSPs) using N-central. N-able has released a patch for the latest RCE vulnerability, but on-premises customers must apply it manually. Administrators are advised to isolate affected servers and audit administrative accounts to mitigate risks.
Key Points: • N-able N-central has critical vulnerabilities with CVSS scores up to 10.0. • Active exploitation of these vulnerabilities has been confirmed by Huntress. • Immediate patching and server isolation are recommended for affected users.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.