N-ABLE has released an emergency hotfix for a high-severity flaw in its N-central remote monitoring and management (RMM) platform, identified as CVE-2026-86218. Described by N-able as a pre-auth remote code execution (RCE), the vulnerability allows an attacker to run code on the N-central server without authentication. The issue is rated CVSS 10.0 (CVSSv4) and has been observed exploited in the wild, with the patch staged across builds.
N-central prior to 2026.3.1.14 is affected, including Hotfix 3, and hosted (NCOD) instances were patched automatically. In practice, this means a compromised on-premises server could immediately compromise all connected endpoints and sessions it manages, elevating the risk to MSP customers and their clients.
Exploitation status remains nuanced. N-able’s incident note states exploitation in the wild has been observed, but the company emphasises there are no confirmations that this vulnerability has been exploited in production environments and urges patching to mitigate ongoing risk. Huntress reported a fully patched customer environment showing signs of intrusion, though which exact exploit was used could not be definitively confirmed.
In addition to CVE-2026-86218, two related flaws patched the same weekend—CVE-2026-86206 (internal API access-control) and CVE-2026-86207 (internal API authentication bypass)—are linked to a chained chain enabling unauthorized admin accounts.
Affected versions span before 2026.3.1.14; patch guidance directs updating to 2026.3 HF4 (build 2026.3.1.14) and then conducting post-patch investigations for anomalous accounts, API activity, and monitoring for exposed management consoles, with IP allowlisting or VPN-restricted access recommended. The scale of exposure, given MSPs’ multi-client reach, underscores the urgency of applying the update promptly.