N-able N-central Pre-Auth RCE Exploited in the Wild
A maximum-severity static code injection flaw in N-central lets an attacker run code on the RMM server without ever logging in.
First Seen: September 4, 2026
Affected Products: N-able N-central
Impact: N-able has patched a maximum-severity flaw in N-central, the remote monitoring and management (RMM) platform that managed service providers and IT teams rely on to run thousands of client devices from a single console. Tracked as CVE-2026-86218 and carrying the worst-possible CVSS score of 10.0, the bug is a static code injection weakness that lets an attacker run their own code on an N-central server without ever logging in. N-able shipped an emergency fix, N-central 2026.3 Hotfix 4, on September 5, 2026, and CISA added the flaw to its Known Exploited Vulnerabilities catalog days later, ordering federal agencies to patch by September 11. No specific threat actor or malware family has been publicly tied to the activity yet, but scanning and exploitation attempts were already underway before the patch landed.
CVE
| CVE | Name | Affected Product | Zero-Day | CISA KEV | Patch |
|---|---|---|---|---|---|
CVE-2026-86218 | N-able N-central Static Code Injection Vulnerability | N-able N-central | Yes | Yes | Yes |
Vulnerability Details
CVE-2026-86206 and CVE-2026-86207 (patched in Hotfix 3), which can be chained to create an attacker-controlled administrator account; investigators were unable to confirm which flaw was used in an early September intrusion because logs on the compromised appliance had already rotated.Vulnerability
| CVE ID | Affected Products | Affected CPE | CWE ID |
|---|---|---|---|
CVE-2026-86218 | N-able N-central (Before 2026.3.1.14) | cpe:2.3:a:n-able:n-central:*:*:*:*:*:*:*:* | CWE-96 |
Recommendations
Upgrade every on-premises N-central deployment to 2026.3 Hotfix 4 (build 2026.3.1.14), which closes this vulnerability. Deployments still on Hotfix 3 are not protected; treat HF4 as mandatory. Hosted N-central environments were already patched server-side by N-able and need no customer action.
Where possible, avoid exposing the N-central management console directly to the open internet. Place it behind a VPN, restrict access to a trusted IP allowlist, and ensure administrative interfaces are reachable only from known networks.
Maintain an accurate inventory of software versions and applied patches, and monitor vendor advisories so emergency hotfixes like this one are applied quickly. Give particular scrutiny to RMM and other management tooling that sits above your wider environment.
Review logs for scanning or connection attempts from the IP range 23.234.64.0/18, which N-able observed probing for this vulnerability. Audit your N-central deployment for unfamiliar or newly created user accounts, especially any unexpected administrator-level accounts.
Potential MITRE ATT&CK TTPs
Patch Links
- n-able.com — N-central security hotfix, September 5, 2026
- status.n-able.com — N-central 2026.3 Hotfix 4 / CVE-2026-86218
References
- me.n-able.com — CVE-2026-86218 security advisory
- documentation.n-able.com — N-central 2026.3 HF4 release notes
What Next?
At Hive Pro, it is our mission to detect the most likely threats to your organization and to help you prevent them from happening.
