N-able has issued an emergency hotfix for CVE-2026-86218, a pre-authentication remote code
execution flaw in its N-central remote monitoring and management (RMM) platform, rated the
maximum CVSS score of 10.0. Because N-central manages large fleets of downstream endpoints, a
single compromised server can be used to run scripts, push tools and open remote sessions across
every device it manages, giving a successful attacker enormous reach. The fix is 2026.3 Hotfix 4 (build
2026.3.1.14), which supersedes Hotfix 3, so on-premises servers still on HF3 remain exposed; hosted
(NCOD) instances have already been patched by N-able. Reporting on exploitation is mixed, with
Huntress and N-able’s incident page describing in-the-wild exploitation while N-able’s release notes say
production exploitation is unconfirmed, but given the severity and RMM reach every on-premises N
central server should be upgraded to HF4 immediately and reviewed for compromise.
1. Vulnerability Details
CVE ID – CVE-2026-86218 (N-able N-central)
CVSS SCORE – 10.0 (maximum; N-able rates it critical-CVSS)
EXPLOIT STATUS – Reports conflict: Huntress, the MSPGeek disclosure and N-able’s Active Incident page
describe in-the-wild exploitation of this zero-day, while N-able’s HF4 release notes state there
are no confirmations of production exploitation but that unpatched systems remain at risk.
CVE-2026-86218 is a pre-authentication remote code execution vulnerability in N-able N-central, responsibly disclosed
by a third party and, per N-able, unrelated to the previously disclosed N-central CVEs. Because N-central is a remote
monitoring and management platform, a compromised server can run scripts, push tools and open remote sessions
across every downstream endpoint it manages, so exploitation of one console can cascade to many organisations.
2. Affected Products
- N-able N-central, on-premises deployments, all builds prior to 2026.3 Hotfix 4 (build 2026.3.1.14), including servers already on Hotfix 3 (build 2026.3.1.13).
- Fix: upgrade to 2026.3 Hotfix 4 (build 2026.3.1.14) immediately. HF4 supersedes HF3. Supported direct upgrade paths include 2025.4, 2026.1, 2026.2, 2026.3, and 2026.3.1 HF1/HF2.
- Hosted N-central (NCOD): already patched by N-able; no customer action required.
3. Exploitation & Impact
The vulnerability is being treated as actively exploited given its severity and the RMM blast radius.
- Conflicting exploitation reports: Huntress, the MSPGeek Discord disclosure and N-able’s Active Incident page describe CVE-2026-86218 as observed exploited in the wild; N-able’s release notes say production exploitation is unconfirmed while unpatched systems remain at risk. Historical appliance logs had often rotated, complicating confirmation of which CVE was used in observed intrusions.
- RMM blast radius: A compromised N-central server can execute scripts, deploy tools and open remote sessions on every managed downstream endpoint, so a single exploited console can lead to compromise across many client environments.
4. Other Notable CVEs
- CVE-2026-86206 / CVE-2026-86207 (CVSS N/A): Access-control bypass chain disclosed 5 Sep 2026 enabling creation of unauthorized administrative accounts; fixed in Hotfix 3 (build 2026.3.1.13). Distinct from CVE-2026-86218.
- CVE-2026-18556 / CVE-2026-18577 (CVSS N/A): August 2026 flaws granting unauthenticated ‘god-mode’ access to the N-central console, exploited in the wild; addressed by the August hotfixes (build 2026.3.1.10).
5. Indicators of Compromise (IOCs)
- https://www.virustotal.com/gui/collection/a07d98ce2a1588897d71da7ca5ed798df0544dbe9e1612fde6
e2c4705059e05d/iocs
6. Recommendations
- Upgrade all on-premises N-able N-central servers to 2026.3 Hotfix 4 (build 2026.3.1.14) immediately. HF4 supersedes HF3, so systems still on HF3 (2026.3.1.13) remain exposed to CVE-2026-86218. Hosted (NCOD) instances are already patched.
- If you cannot patch at once, restrict N-central to internal and trusted networks and remove it from interne exposure; because the flaw is pre-authentication, consider temporarily taking the server offline until HF4 is applied, as Huntress advises.
- Assume potential compromise given the RMM reach: review N-central for suspicious logins, remote-control sessions and script or tool pushes across the exposure window, and check the appliance logs for evidence of API manipulation.
- Audit N-central user accounts for unauthorised changes and anomalous administrator-account creation, for example accounts using .invalid email addresses, per Huntress’s guidance on the related CVE-2026 86206/86207 chain.
- If compromise is found, treat downstream managed endpoints as potentially affected: hunt for attacker deployed scripts, tools and remote sessions across managed devices, rotate N-central and connected credentials, and rebuild the server.
- Confirm the earlier hotfixes for the related N-central CVEs are also applied (the August build 2026.3.1.10 for CVE-2026-18556/18577 and Hotfix 3 for CVE-2026-86206/86207), and track N-able’s status and Active Incident pages for updates.
- Block the IOCs at their respective controls, https://www.virustotal.com/gui/collection/a07d98ce2a15 88897d71da7ca5ed798df0544dbe9e1612fde6e2c4705059e05d/iocs
7. Sources
- https://www.huntress.com/blog/n-able-vulnerability-exploitation
- https://status.n-able.com/2026/09/06/n-central-2026-3-hotfix-4-cve-2026-86218/
- https://www.virustotal.com/gui/collection/a07d98ce2a1588897d71da7ca5ed798df0544dbe9e1612fde
6e2c4705059e05d/iocs
Enjoyed reading this Threat Intelligence Advisory? Stay updated with our latest exclusive content by following us on Twitter and LinkedIn
No related posts found.