N-able Patches Critical RCE Vulnerability in N-central Platform
N-able, a managed IT software provider, has released a hotfix addressing a critical remote code execution (RCE) vulnerability in its N-central remote monitoring and management platform. Tracked as CVE-2026-86218, the flaw carries a maximum-severity CVSS score of 10 and was disclosed on September 6.
The pre-authentication RCE vulnerability affects N-central versions prior to 2026.3.1.14, allowing unauthenticated attackers to execute arbitrary code on the server. While N-able has not disclosed the affected component or exploitation method, the company confirmed no evidence of active exploitation in production environments. The patch was included in N-central 2026.3 Hotfix 4 (build 2026.3.1.14).
This is the latest in a series of vulnerabilities impacting N-able products in recent weeks. Earlier in 2026, two high-severity authentication bypass flaws (CVE-2026-18556 and CVE-2026-18577) were exploited in the wild and added to CISA’s Known Exploited Vulnerabilities (KEV) catalog in August. Patches for those vulnerabilities were released in Hotfix 1 (August 2) and Hotfix 2 (August 6).
Additional high-severity flaws patched in Hotfix 3 (September 5) include:
- CVE-2026-86207: An authentication bypass affecting internal APIs.
- CVE-2026-86206: An access-control filter bypass exposing internal APIs.
Organizations using N-central are advised to apply the latest hotfix to mitigate risks.
Source: https://www.infosecurity-magazine.com/news/nable-hotfix-critical-rce/
N-able TPRM report: https://www.rankiteo.com/company/n-able
"id": "n-a1788791461",
"linkid": "n-able",
"type": "Vulnerability",
"date": "9/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Information Technology',
'name': 'N-able',
'type': 'Managed IT software provider'}],
'attack_vector': 'Unauthenticated remote access',
'date_publicly_disclosed': '2026-09-06',
'description': 'N-able, a managed IT software provider, has released a hotfix '
'addressing a critical remote code execution (RCE) '
'vulnerability in its N-central remote monitoring and '
'management platform. Tracked as CVE-2026-86218, the flaw '
'carries a maximum-severity CVSS score of 10 and allows '
'unauthenticated attackers to execute arbitrary code on the '
'server. The patch was included in N-central 2026.3 Hotfix 4 '
'(build 2026.3.1.14).',
'impact': {'systems_affected': 'N-central remote monitoring and management '
'platform (versions prior to 2026.3.1.14)'},
'investigation_status': 'No evidence of active exploitation in production '
'environments',
'recommendations': 'Organizations using N-central are advised to apply the '
'latest hotfix to mitigate risks.',
'references': [{'source': 'N-able Security Advisory'}],
'response': {'containment_measures': 'Hotfix released (N-central 2026.3 '
'Hotfix 4, build 2026.3.1.14)',
'remediation_measures': 'Patching vulnerable N-central versions'},
'title': 'N-able Patches Critical RCE Vulnerability in N-central Platform',
'type': 'Remote Code Execution (RCE)',
'vulnerability_exploited': 'CVE-2026-86218'}