N-ABLE has rolled out an urgent fix for an unauthenticated remote code execution vulnerability in its N-central endpoint management platform, tracked as CVE-2026-86218, which security researchers describe as a zero-day that had been exploited. The flaw carries a CVSS score of 10/10 and was discovered after N-able patched two prior issues in N-central, CVE-2026-86206 and CVE-2026-86207. N-able warns that the critical zero-day could allow pre-authenticated access to the N-central server if exploited.
The company states that hosted N-central deployments do not require action because patches were applied server-side, while on-premises instances must immediately apply the 2026.3 HF4 hotfix.
Administrators are advised to scrutinise logs for signs of exploitation, specifically noting scans originating from the IP range 23.234.64[.]0/18. In addition, organisations should review their deployments for newly created user accounts that they do not recognise.
While N-able says there are currently no confirmations of exploitation in production environments and unpatched systems remain at risk, the hotfix for CVE-2026-86218 supersedes the earlier patches for CVE-2026-86206 and CVE-2026-86207, which Huntress had flagged as potentially chained in the wild to bypass authentication and compromise N-central production environments.
Observations from Huntress indicate attacks targeting N-central’s underlying API and appliance logs began on 4 September 2026, though direct attribution to a specific exploit remains uncertain due to limited historical logging on the appliance.