Start with Identity
← Blog
News

N-able shipped a fourth N-central hotfix in five weeks, and CVSS 10.0 was already exploited

CVE-2026-86218 is a static code injection giving pre-auth RCE on N-central, scoring 10.0 and exploited in the wild. Huntress found a compromised customer on September 4; CISA set a federal deadline of September 11.

By SWI Community TeamSep 9, 2026Updated Sep 14, 2026

CVE-2026-86218, a static code injection flaw giving pre-authentication remote code execution in N-able N-central, carries a CVSS score of 10.0 and is being exploited in the wild. Huntress detected a compromised customer on September 4, 2026. N-able released N-central 2026.3 Hotfix 4 the following day, and Hotfix 3 the same day for CVE-2026-86206 and CVE-2026-86207, which chain to bypass authentication and create an attacker-controlled System Administrator account without credentials. CISA added CVE-2026-86218 to its Known Exploited Vulnerabilities catalog on September 8, with a federal remediation deadline of September 11. It is the fourth N-central hotfix in five weeks.

Why it matters

We have now covered this product three times: the incomplete first fix on August 3, confirmed use against managed customer networks on August 7, and this. Four hotfixes in five weeks is not a patching story, it is a signal about the code around the authentication boundary, and the right response is to stop treating each advisory as an isolated event.

N-central manages entire IT estates for MSPs, so an administrator account here is an administrator account at every downstream customer. That concentration is why RMM platforms keep appearing in ransomware initial-access reporting, and why the Qilin affiliates and Cl0p operators we track keep finding them.

If you run N-central, patching to Hotfix 4 is the floor, not the response. Assume the pre-Hotfix window was exposed: enumerate System Administrator accounts and API tokens created since early August, revoke and reissue agent credentials, review the actions taken through the platform against customer estates in that period, and rotate the credentials N-central holds for those estates. An attacker who created an administrator on August 6 is unaffected by a September 5 patch.

Source: The Hacker News

Last reviewed By SWI Community TeamSuggest a correctionHow we research
Independent analysis. No vendor sponsorship.