Threat Intelligence

Critical N-able N-central Flaw Actively Exploited, CISA Sets Patch Deadline

The Hacker News · 9 Sept 2026
Key Takeaway If your business uses an IT provider running N-able N-central, confirm with them urgently that the latest security hotfix has been applied.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical flaw in N-able N-central, a remote monitoring and management platform used by many IT providers, to its Known Exploited Vulnerabilities catalog. The vulnerability, CVE-2026-86218, scored the maximum possible severity rating of 10.0 and allows attackers to remotely execute code on a target system without needing to log in first. It was fixed in N-central 2026.3 Hotfix 4, released on September 5, 2026.

The flaw came to light after security firm Huntress began investigating the compromise of a customer's fully patched N-central environment on September 4, 2026. Investigators noted that limited logging on the appliance made it difficult to confirm exactly which vulnerability was used, and could not rule out two other related flaws (CVE-2026-86206 and CVE-2026-86207) that were patched around the same time and can be chained to create a rogue administrator account.

N-able has confirmed CVE-2026-86218 is being actively exploited and is urging all customers to apply the hotfix immediately. Because N-central is widely used by managed service providers to oversee client systems, a successful attack could give hackers a foothold into many downstream business networks at once.

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.