N-able Rushes Out Emergency Fix for Critical RCE Flaw in N-central Platform
N-able releases an emergency hotfix for a maximum-severity remote code execution flaw affecting its N-central remote monitoring and management platform. The vulnerability, tracked as CVE-2026-86218, allows unprivileged threat actors to execute malicious code on unpatched instances exposed to the internet through low-complexity attacks. The company addresses the issue with N-central 2026.3 Hotfix 4 and urges customers running on-premises deployments to upgrade immediately.
While N-able says it has no confirmations that the vulnerability is exploited in production environments, cybersecurity firm Huntress flags it as a potential zero-day. Huntress links it to two additional high-severity flaws, CVE-2026-86206 and CVE-2026-86207, which allow attackers to bypass authentication and gain full access to vulnerable N-central platforms. Huntress investigates a compromised server at one of its customers but cannot determine which flaw the attackers exploited because the relevant logs have already rotated.
The Shadowserver Foundation now tracks nearly 1,500 N-central servers exposed online, with most located in the United States and Europe. Huntress warns that systems still running Hotfix 3 remain vulnerable to the newly disclosed flaw and must apply HF4 immediately. The update arrives one year after N-able patched two other N-central vulnerabilities that attackers were actively exploiting in the wild.