N-able: N-able Releases Hotfix for Critical Remote Code Execution Flaw

N-able: N-able Releases Hotfix for Critical Remote Code Execution Flaw

N-able Patches Critical RCE Vulnerability in N-central Platform

N-able, a managed IT software provider, has released a hotfix addressing a critical remote code execution (RCE) vulnerability in its N-central remote monitoring and management platform. Tracked as CVE-2026-86218, the flaw carries a maximum-severity CVSS score of 10 and was disclosed on September 6.

The pre-authentication RCE vulnerability affects N-central versions prior to 2026.3.1.14, allowing unauthenticated attackers to execute arbitrary code on the server. While N-able has not disclosed the affected component or exploitation method, the company confirmed no evidence of active exploitation in production environments. The patch was included in N-central 2026.3 Hotfix 4 (build 2026.3.1.14).

This is the latest in a series of vulnerabilities impacting N-able products in recent weeks. Earlier in 2026, two high-severity authentication bypass flaws (CVE-2026-18556 and CVE-2026-18577) were exploited in the wild and added to CISA’s Known Exploited Vulnerabilities (KEV) catalog in August. Patches for those vulnerabilities were released in Hotfix 1 (August 2) and Hotfix 2 (August 6).

Additional high-severity flaws patched in Hotfix 3 (September 5) include:

  • CVE-2026-86207: An authentication bypass affecting internal APIs.
  • CVE-2026-86206: An access-control filter bypass exposing internal APIs.

Organizations using N-central are advised to apply the latest hotfix to mitigate risks.

Source: https://www.infosecurity-magazine.com/news/nable-hotfix-critical-rce/

N-able TPRM report: https://www.rankiteo.com/company/n-able

"id": "n-a1788791461",
"linkid": "n-able",
"type": "Vulnerability",
"date": "9/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Information Technology',
                        'name': 'N-able',
                        'type': 'Managed IT software provider'}],
 'attack_vector': 'Unauthenticated remote access',
 'date_publicly_disclosed': '2026-09-06',
 'description': 'N-able, a managed IT software provider, has released a hotfix '
                'addressing a critical remote code execution (RCE) '
                'vulnerability in its N-central remote monitoring and '
                'management platform. Tracked as CVE-2026-86218, the flaw '
                'carries a maximum-severity CVSS score of 10 and allows '
                'unauthenticated attackers to execute arbitrary code on the '
                'server. The patch was included in N-central 2026.3 Hotfix 4 '
                '(build 2026.3.1.14).',
 'impact': {'systems_affected': 'N-central remote monitoring and management '
                                'platform (versions prior to 2026.3.1.14)'},
 'investigation_status': 'No evidence of active exploitation in production '
                         'environments',
 'recommendations': 'Organizations using N-central are advised to apply the '
                    'latest hotfix to mitigate risks.',
 'references': [{'source': 'N-able Security Advisory'}],
 'response': {'containment_measures': 'Hotfix released (N-central 2026.3 '
                                      'Hotfix 4, build 2026.3.1.14)',
              'remediation_measures': 'Patching vulnerable N-central versions'},
 'title': 'N-able Patches Critical RCE Vulnerability in N-central Platform',
 'type': 'Remote Code Execution (RCE)',
 'vulnerability_exploited': 'CVE-2026-86218'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.