N-ABLE has issued a hotfix addressing a critical remote code execution (RCE) vulnerability in its N-central platform, the company’s remote monitoring and management (RMM) product. CVE-2026-86218 is a pre-authentication RCE flaw rated CVSS 10, affecting N-central versions prior to 2026.3.1.14. N-able disclosed the vulnerability on 6 September and said there is no public detail on the affected component or exploitation method, but it has found no evidence of active exploitation in production environments. The patch is included in N-central 2026.3 Hotfix 4, bringing the build to 2026.3.1.14.
This hotfix follows a cluster of other N-able fixes released over the past weeks. CVE-2026-18556 and CVE-2026-18577 are high-severity authentication bypasses that were exploited earlier in 2026 and added to the US CISA KEV catalogue in August; patches were delivered via HF1 (2 August) and HF2 (6 August).
Additionally, CVE-2026-86207 (high-severity authentication bypass affecting internal APIs) and CVE-2026-86206 (high-severity access-control filter bypass exposing internal APIs) were addressed in HF3 on 5 September.
In summary, organisations running vulnerable N-central versions should apply N-central 2026.3 Hotfix 4 (to 2026.3.1.14) promptly, alongside the prior HF1–HF3 patches for other CVEs, to mitigate multiple high-risk vulnerabilities. The article does not report any current exploitation of CVE-2026-86218.