
N-able has released an emergency hotfix for a Maximum Severity Remote Code Execution (RCE) flaw affecting its N-central Remote Monitoring and Management (RMM) platform.
IT departments and managed service providers (MSPs) use the N-central platform to monitor, manage and support customer networks and devices from a centralized web-based console.
Tracked as CVE-2026-86218this RCE vulnerability allows unprivileged threat actors to execute malicious code on unspoiled copies of N-central exposed online in low-sophistication attacks.
N-able addressed the shortcoming on Saturday by releasing N-central 2026.3 Update Patch 4 and urges customers to make a correction as soon as possible.
“We currently have no confirmation that this vulnerability has been exploited in production environments, but systems without patches remain at risk,” the company said.
“Customers running on-premises N-central deployments should upgrade to N-central 2026.3 HF4 immediately to protect their environment.”
The Internet security nonprofit Shadowserver Foundation is already tracking nearly 1500 N-central servers exposed onlinewith most of them located in the United States and Europe.

Proof of active operation
Although N-able has not yet confirmed that the CVE-2026-86218 flaw is targeted, cybersecurity firm Huntress has flagged it as a potential zero-day, along with two high-severity vulnerabilities (tracked as CVE-2026-86206 and CVE-2026-86207 , and also patched over the weekend), which may allow attackers to bypass authentication and gain full access to the vulnerable N-central platform.
“In our 9/5/26 update (..) we said that we cannot rule out whether the two previous vulnerabilities are released (CVE-2026-86206 and CVE-2026-86207) were the ones used in the case seen in one of our customers’ patched production environment,” said Huntress.
“Since the logs of the compromised N-central server have already rotated, we also cannot say if this new CVE is the vulnerability used in this case.”
“Local N-central users should implement HF4 immediately, as systems running HF3 remain vulnerable to this newly discovered flaw,” Huntress warned.
A year ago, N-able released security updates for two N-central vulnerabilities (CVE-2025-8875 and CVE-2025-8876) that attackers were exploiting in the wild.
Days later, Shadowserver found that 880 N-central servers were still vulnerable to attacks using the two security flaws, even after CISA ordered federal agencies to patch their systems within a week and urged all security teams to also prioritize protecting their systems against ongoing attacks.
Generic prevention scores can hide what happens after initial access. Once attackers use valid credentials, prevention plummets.
The 2026 Blue Report measures security techniques by techniques in 338 million simulations run in customer production environments.
