N-able N-central Pre-Auth RCE Exploited in the Wild (CVE-2026-86218)

Red | Vulnerability
N-able N-central Pre-Auth RCE Exploited in the Wild (CVE-2026-86218)
HiveForce Labs Threat Advisory · Vulnerability Report

N-able N-central Pre-Auth RCE Exploited in the Wild

A maximum-severity static code injection flaw in N-central lets an attacker run code on the RMM server without ever logging in.

TA2026265Threat Level: RedAdmiralty Code: A1Published Sep 10, 2026CVE-2026-86218CVSS 10.0
First SeenSep 4, 2026
CVECVE-2026-86218
CVSS Score10.0
Zero-DayYes
CISA KEVYes
Patch AvailableYes
CWECWE-96
KEV DeadlineSep 11, 2026
Report TypeVulnerability

First Seen: September 4, 2026

Affected Products: N-able N-central

Impact: N-able has patched a maximum-severity flaw in N-central, the remote monitoring and management (RMM) platform that managed service providers and IT teams rely on to run thousands of client devices from a single console. Tracked as CVE-2026-86218 and carrying the worst-possible CVSS score of 10.0, the bug is a static code injection weakness that lets an attacker run their own code on an N-central server without ever logging in. N-able shipped an emergency fix, N-central 2026.3 Hotfix 4, on September 5, 2026, and CISA added the flaw to its Known Exploited Vulnerabilities catalog days later, ordering federal agencies to patch by September 11. No specific threat actor or malware family has been publicly tied to the activity yet, but scanning and exploitation attempts were already underway before the patch landed.

CVE

CVENameAffected ProductZero-DayCISA KEVPatch
CVE-2026-86218N-able N-central Static Code Injection VulnerabilityN-able N-centralYesYesYes

Vulnerability Details

#1
CVE-2026-86218 is a critical zero-day code injection vulnerability in N-able N-central, the web-based console MSPs and large IT organizations use to monitor and manage client networks. The flaw stems from the server accepting attacker-controlled input and treating it as executable code rather than inert data. The practical result is pre-authentication remote code execution: an attacker can run commands on the N-central server before any login or authentication step, which is what pushes the severity to the maximum.
#2
The vulnerability is exploitable remotely against internet-facing N-central instances in low-complexity attacks that require no privileges and no user interaction. Because N-central is designed to reach down into every device and customer environment it manages, code executed on the server does not stay contained to the appliance; changes made through a compromised N-central can propagate across all connected systems, which is exactly why the platform is so attractive to ransomware operators.
#3
The issue affects N-central builds before 2026.3.1.14, delivered as N-central 2026.3 Hotfix 4. Deployments still running the earlier Hotfix 3 remain exposed to this specific flaw, so HF3 is not a sufficient fix. Both hosted and on-premises deployments were listed as impacted; N-able patched hosted environments server-side, while on-premises operators must apply the update themselves.
#4
CVE-2026-86218 carries a CVSS score of 10.0, while N-able’s own urgent customer notice stated the flaw had been observed being exploited in the wild — before a patch was available. The disclosure landed on the heels of two related authentication-bypass flaws in N-central, CVE-2026-86206 and CVE-2026-86207 (patched in Hotfix 3), which can be chained to create an attacker-controlled administrator account; investigators were unable to confirm which flaw was used in an early September intrusion because logs on the compromised appliance had already rotated.

Vulnerability

CVE IDAffected ProductsAffected CPECWE ID
CVE-2026-86218N-able N-central (Before 2026.3.1.14)cpe:2.3:a:n-able:n-central:*:*:*:*:*:*:*:*CWE-96

Recommendations

01
Apply Hotfix 4 Without Delay

Upgrade every on-premises N-central deployment to 2026.3 Hotfix 4 (build 2026.3.1.14), which closes this vulnerability. Deployments still on Hotfix 3 are not protected; treat HF4 as mandatory. Hosted N-central environments were already patched server-side by N-able and need no customer action.

02
Reduce Internet Exposure

Where possible, avoid exposing the N-central management console directly to the open internet. Place it behind a VPN, restrict access to a trusted IP allowlist, and ensure administrative interfaces are reachable only from known networks.

03
Maintain Vulnerability Management Discipline

Maintain an accurate inventory of software versions and applied patches, and monitor vendor advisories so emergency hotfixes like this one are applied quickly. Give particular scrutiny to RMM and other management tooling that sits above your wider environment.

04
Hunt for Signs of Compromise

Review logs for scanning or connection attempts from the IP range 23.234.64.0/18, which N-able observed probing for this vulnerability. Audit your N-central deployment for unfamiliar or newly created user accounts, especially any unexpected administrator-level accounts.


Potential MITRE ATT&CK TTPs

Initial Access
T1190: Exploit Public-Facing Application
Execution
T1059: Command and Scripting Interpreter
Resource Development
T1588: Obtain Capabilities → T1588.006 Vulnerabilities

Patch Links


References

What Next?

At Hive Pro, it is our mission to detect the most likely threats to your organization and to help you prevent them from happening.

Reduce real exposure. Not just vulnerability volume.