Ethical Hacking News
N-able's Critical N-central Flaw: A Vulnerability that Raises Concerns about Unauthenticated Remote Code Execution. N-able has released its fourth hotfix in just five weeks to address a critical vulnerability in its N-central platform, which could allow remote code execution on the N-central server without authentication. The vulnerability affects every N-central build before 2026.3.1.14 and has raised concerns about unauthenticated remote code execution.
N-able has released its fourth hotfix in five weeks to address a critical vulnerability in its N-central platform (CVE-2026-86218) with a CVSS score of 10.0. The vulnerability affects every N-central build before 2026.3.1.14, including servers updated to Hotfix 3. Hosted N-central instances have already been patched, while on-premises customers are advised to upgrade to 2026.3.1.14 immediately. N-able has stated that agents do not need to be upgraded to be protected from this CVE. Huntress advises administrators to restrict inbound access to the console with IP allowlisting or a VPN and consider taking it offline until the hotfix is applied. The question of exploitation is contentious, with N-able's channels diverging on the issue. N-able claims a third-party disclosed the vulnerability, but Huntress cannot confirm exploitation. The N-central platform has been targeted in the past, with the U.S. CISA adding two other flaws in 2025. N-able continues to monitor the situation and provide updates as necessary.
N-able, a leading provider of remote monitoring and management (RMM) solutions, has recently released its fourth hotfix in just five weeks to address a critical vulnerability in its N-central platform. The vulnerability, tracked as CVE-2026-86218, carries a CVSS 4.0 score of 10.0, indicating a maximum-severity vulnerability that could allow remote code execution on the N-central server without authentication.
The vulnerability affects every N-central build before 2026.3.1.14, including servers updated to Hotfix 3 (2026.3.1.13), which was published just over eight hours earlier for two unrelated flaws. N-able has stated that hosted N-central (NCOD) instances have already been patched, while on-premises customers are advised to upgrade to 2026.3.1.14 immediately.
The release notes for the hotfix provide direct upgrade paths from 2025.4, 2026.1, 2026.2, 2026.3, and the 2026.3.1 hotfixes, indicating that agents do not need to be upgraded to be protected from this CVE. However, Huntress, a cybersecurity company that has been tracking attacks on N-central, has advised administrators to restrict inbound access to the console with IP allowlisting or a VPN and, where a server is still reachable from the internet, to consider taking it offline until the hotfix is applied.
The question of exploitation is a contentious one, with N-able's channels diverging on the issue. The Hotfix 4 release notes and status post state that a third party responsibly disclosed the vulnerability through N-able's security disclosure program and that N-able has "no confirmations that this vulnerability has been exploited in production environments." However, N-able's incident notice on its uptime status page claims that a third, independent security researcher alerted the company to a new vulnerability unrelated to the previously disclosed CVEs and that this newly identified flaw "has been observed being exploited in the wild."
Huntress has stated that it cannot settle the question from its own data, and the company began investigating on September 4 after a customer's fully patched N-central production environment was compromised. It said it reproduced a proof-of-concept exploit chain against build 2026.3.1.10 that may use one or both of the two flaws later fixed in Hotfix 3, but the appliance's logs had already rotated, leaving it "unable to say whether this new CVE was the vulnerability exploited" in that intrusion.
This latest hotfix marks the fourth one released by N-able for the 2026.3 line since August 2, addressing a distinct set of vulnerabilities. The previous hotfixes have covered CVE-2026-18577, an incomplete fix for CVE-2026-18556 that still allowed authentication bypass and account takeover; Hotfix 2 (2026.3.1.10), which provided additional hardening for a related attack path; and Hotfix 3 (2026.3.1.13), which addressed CVE-2026-86206, unauthorized access to internal APIs through the access control filter, and CVE-2026-86207, an authentication bypass in internal-only APIs.
The N-central platform has drawn attention in the past due to in-the-wild attacks, with the U.S. Cybersecurity and Infrastructure Security Agency (CISA) adding two other flaws in the product, CVE-2025-8875 and CVE-2025-8876, to its Known Exploited Vulnerabilities catalog in August 2025. N-able has stated that a full root-cause analysis is coming for the 2025.4 vulnerability.
In light of this latest vulnerability, it is essential for N-central customers to take proactive measures to protect themselves. Huntress advises restricting inbound access to the console with IP allowlisting or a VPN and, where a server is still reachable from the internet, considering taking it offline until the hotfix is applied. Meanwhile, N-able continues to monitor the situation and provide updates as necessary.
Related Information:
https://www.ethicalhackingnews.com/articles/N-ables-Critical-N-central-Flaw-A-Vulnerability-that-Raises-Concerns-about-Unauthenticated-Remote-Code-Execution-ehn.shtml
https://thehackernews.com/2026/09/n-able-issues-fourth-n-central-hotfix.html
https://nvd.nist.gov/vuln/detail/CVE-2026-86218
https://www.cvedetails.com/cve/CVE-2026-86218/
https://nvd.nist.gov/vuln/detail/CVE-2026-18577
https://www.cvedetails.com/cve/CVE-2026-18577/
https://nvd.nist.gov/vuln/detail/CVE-2026-18556
https://www.cvedetails.com/cve/CVE-2026-18556/
https://nvd.nist.gov/vuln/detail/CVE-2026-86206
https://www.cvedetails.com/cve/CVE-2026-86206/
https://nvd.nist.gov/vuln/detail/CVE-2026-86207
https://www.cvedetails.com/cve/CVE-2026-86207/
https://nvd.nist.gov/vuln/detail/CVE-2025-8875
https://www.cvedetails.com/cve/CVE-2025-8875/
https://nvd.nist.gov/vuln/detail/CVE-2025-8876
https://www.cvedetails.com/cve/CVE-2025-8876/
Published: Mon Sep 7 05:40:31 2026 by llama3.2 3B Q4_K_M