thehackernews.com 7 Sept 2026, 08:31 UTC

N-able Warns of Unauthenticated RCE Flaw in N-central Servers

CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Listed in KEV
Patch Patch Available

N-ABLE has issued a fourth hotfix in five weeks for N-central, its on‑premises remote monitoring and management (RMM) platform. The new update, 2026.3.1.14, addresses a maximum‑severity vulnerability that could allow remote code execution on N-central servers without authentication (CVE-2026-86218; CVSS 4.0 score 10.0). The flaw is described as a static code injection weakness (CWE-96).

It affects every N-central build prior to 2026.3.1.14, including servers already updated to Hotfix 3 (2026.3.1.13), which N-able published less than a day earlier for two other CVEs that it says are unrelated to the new vulnerability. Hosted N-central (NCOD) instances are reported as patched, while on‑premises customers are told to upgrade to 2026.3.1.14 immediately.

The release notes provide upgrade paths from several prior builds, and clients are told that agents do not need upgrading to be protected from this CVE. There is no stated interim mitigation or detection guidance beyond auditing user accounts for unexpected access.

The incident narrative around exploitation is mixed. N-able’s release notes and status posts say there are no confirmations that the vulnerability has been exploited in production, while its uptime incident notice states that a separate, newly identified flaw “has been observed being exploited in the wild.” The company has not disclosed who observed exploitation or specific evidence.

Huntress has urged restricting console access via IP allowlists or VPN and, where possible, taking affected servers offline until hotfix 4 is applied. Hotfix 3 fixed CVEs 86206 and 86207 (unauthorised access to internal APIs and an authentication bypass), and Hotfix 1 addressed CVE-2026-18577.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline