N-able Patches Critical Flaw in N-central Remote Management Platform
Managed IT software provider N-able has released a hotfix addressing a critical remote code execution vulnerability in N-central, its remote monitoring and management platform. Tracked as CVE-2026-86218, the flaw carries the maximum CVSS score of 10 and can allow an unauthenticated attacker to execute code on an N-central server without needing valid credentials. It affects all N-central versions before 2026.3.1.14.
N-able has not disclosed which component is affected or how the flaw could be exploited, and says it has found no evidence of the vulnerability being used in real-world attacks so far. A patch is available in N-central 2026.3 Hotfix 4, which updates the build to version 2026.3.1.14.
This marks the fifth vulnerability disclosed in N-able products within a few weeks. Two earlier high-severity authentication bypass flaws, CVE-2026-18556 and CVE-2026-18577, were confirmed as actively exploited and added to CISA's Known Exploited Vulnerabilities catalog in August, with fixes issued in prior hotfixes. Two further high-severity issues involving internal API access were patched on September 5.