CVE-2026-86218: N-able N-central Pre-Auth RCE Flaw Under Active Exploitation

Share:

N-able has issued an emergency hotfix for CVE-2026-86218, a pre-authentication remote code
execution flaw in its N-central remote monitoring and management (RMM) platform, rated the
maximum CVSS score of 10.0. Because N-central manages large fleets of downstream endpoints, a
single compromised server can be used to run scripts, push tools and open remote sessions across
every device it manages, giving a successful attacker enormous reach. The fix is 2026.3 Hotfix 4 (build
2026.3.1.14), which supersedes Hotfix 3, so on-premises servers still on HF3 remain exposed; hosted
(NCOD) instances have already been patched by N-able. Reporting on exploitation is mixed, with
Huntress and N-able’s incident page describing in-the-wild exploitation while N-able’s release notes say
production exploitation is unconfirmed, but given the severity and RMM reach every on-premises N
central server should be upgraded to HF4 immediately and reviewed for compromise.

1. Vulnerability Details

CVE ID – CVE-2026-86218 (N-able N-central)
CVSS SCORE – 10.0 (maximum; N-able rates it critical-CVSS)
EXPLOIT STATUS – Reports conflict: Huntress, the MSPGeek disclosure and N-able’s Active Incident page
describe in-the-wild exploitation of this zero-day, while N-able’s HF4 release notes state there
are no confirmations of production exploitation but that unpatched systems remain at risk.

CVE-2026-86218 is a pre-authentication remote code execution vulnerability in N-able N-central, responsibly disclosed
by a third party and, per N-able, unrelated to the previously disclosed N-central CVEs. Because N-central is a remote
monitoring and management platform, a compromised server can run scripts, push tools and open remote sessions
across every downstream endpoint it manages, so exploitation of one console can cascade to many organisations.

2. Affected Products

  • N-able N-central, on-premises deployments, all builds prior to 2026.3 Hotfix 4 (build 2026.3.1.14), including servers already on Hotfix 3 (build 2026.3.1.13).
  • Fix: upgrade to 2026.3 Hotfix 4 (build 2026.3.1.14) immediately. HF4 supersedes HF3. Supported direct upgrade paths include 2025.4, 2026.1, 2026.2, 2026.3, and 2026.3.1 HF1/HF2.
  • Hosted N-central (NCOD): already patched by N-able; no customer action required.

3. Exploitation & Impact

The vulnerability is being treated as actively exploited given its severity and the RMM blast radius.

  • Conflicting exploitation reports: Huntress, the MSPGeek Discord disclosure and N-able’s Active Incident page describe CVE-2026-86218 as observed exploited in the wild; N-able’s release notes say production exploitation is unconfirmed while unpatched systems remain at risk. Historical appliance logs had often rotated, complicating confirmation of which CVE was used in observed intrusions.
  • RMM blast radius: A compromised N-central server can execute scripts, deploy tools and open remote sessions on every managed downstream endpoint, so a single exploited console can lead to compromise across many client environments.

4. Other Notable CVEs

  • CVE-2026-86206 / CVE-2026-86207 (CVSS N/A): Access-control bypass chain disclosed 5 Sep 2026 enabling creation of unauthorized administrative accounts; fixed in Hotfix 3 (build 2026.3.1.13). Distinct from CVE-2026-86218.
  • CVE-2026-18556 / CVE-2026-18577 (CVSS N/A): August 2026 flaws granting unauthenticated ‘god-mode’ access to the N-central console, exploited in the wild; addressed by the August hotfixes (build 2026.3.1.10).

5. Indicators of Compromise (IOCs)

  • https://www.virustotal.com/gui/collection/a07d98ce2a1588897d71da7ca5ed798df0544dbe9e1612fde6
    e2c4705059e05d/iocs

6. Recommendations

  • Upgrade all on-premises N-able N-central servers to 2026.3 Hotfix 4 (build 2026.3.1.14) immediately. HF4 supersedes HF3, so systems still on HF3 (2026.3.1.13) remain exposed to CVE-2026-86218. Hosted (NCOD) instances are already patched.
  • If you cannot patch at once, restrict N-central to internal and trusted networks and remove it from interne exposure; because the flaw is pre-authentication, consider temporarily taking the server offline until HF4 is applied, as Huntress advises.
  • Assume potential compromise given the RMM reach: review N-central for suspicious logins, remote-control sessions and script or tool pushes across the exposure window, and check the appliance logs for evidence of API manipulation.
  • Audit N-central user accounts for unauthorised changes and anomalous administrator-account creation, for example accounts using .invalid email addresses, per Huntress’s guidance on the related CVE-2026 86206/86207 chain.
  • If compromise is found, treat downstream managed endpoints as potentially affected: hunt for attacker deployed scripts, tools and remote sessions across managed devices, rotate N-central and connected credentials, and rebuild the server.
  • Confirm the earlier hotfixes for the related N-central CVEs are also applied (the August build 2026.3.1.10 for CVE-2026-18556/18577 and Hotfix 3 for CVE-2026-86206/86207), and track N-able’s status and Active Incident pages for updates.
  • Block the IOCs at their respective controls, https://www.virustotal.com/gui/collection/a07d98ce2a15 88897d71da7ca5ed798df0544dbe9e1612fde6e2c4705059e05d/iocs

7. Sources

  • https://www.huntress.com/blog/n-able-vulnerability-exploitation
  • https://status.n-able.com/2026/09/06/n-central-2026-3-hotfix-4-cve-2026-86218/
  • https://www.virustotal.com/gui/collection/a07d98ce2a1588897d71da7ca5ed798df0544dbe9e1612fde
    6e2c4705059e05d/iocs

Enjoyed reading this Threat Intelligence Advisory? Stay updated with our latest exclusive content by following us on Twitter and LinkedIn

No related posts found.

Ampcus Cyber
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Talk to an expert