N-able shipped a fourth N-central hotfix in five weeks, and CVSS 10.0 was already exploited
CVE-2026-86218 is a static code injection giving pre-auth RCE on N-central, scoring 10.0 and exploited in the wild. Huntress found a compromised customer on September 4; CISA set a federal deadline of September 11.
CVE-2026-86218, a static code injection flaw giving pre-authentication remote code execution in N-able N-central, carries a CVSS score of 10.0 and is being exploited in the wild. Huntress detected a compromised customer on September 4, 2026. N-able released N-central 2026.3 Hotfix 4 the following day, and Hotfix 3 the same day for CVE-2026-86206 and CVE-2026-86207, which chain to bypass authentication and create an attacker-controlled System Administrator account without credentials. CISA added CVE-2026-86218 to its Known Exploited Vulnerabilities catalog on September 8, with a federal remediation deadline of September 11. It is the fourth N-central hotfix in five weeks.
Why it matters
We have now covered this product three times: the incomplete first fix on August 3, confirmed use against managed customer networks on August 7, and this. Four hotfixes in five weeks is not a patching story, it is a signal about the code around the authentication boundary, and the right response is to stop treating each advisory as an isolated event.
N-central manages entire IT estates for MSPs, so an administrator account here is an administrator account at every downstream customer. That concentration is why RMM platforms keep appearing in ransomware initial-access reporting, and why the Qilin affiliates and Cl0p operators we track keep finding them.
If you run N-central, patching to Hotfix 4 is the floor, not the response. Assume the pre-Hotfix window was exposed: enumerate System Administrator accounts and API tokens created since early August, revoke and reissue agent credentials, review the actions taken through the platform against customer estates in that period, and rotate the credentials N-central holds for those estates. An attacker who created an administrator on August 6 is unaffected by a September 5 patch.
Source: The Hacker News
Related on Start with Identity
- BlogNetScaler ships a critical authentication bypass affecting Gateway and AAA virtual servers
CVE-2026-19490 (CVSS 9.3) bypasses authentication on NetScaler ADC and Gateway appliances running a Gateway or AAA virtual server, with a SAML action configured
- BlogTwo Cisco FMC flaws are being used to harvest credentials and to land Qilin ransomware
CVE-2026-20079 (CVSS 10.0) gives unauthenticated root on Cisco Secure Firewall Management Center, used to deploy web shells that query internal databases for cr
- BlogA 9.8-CVSS vCenter authentication bypass has no workaround, only an emergency patch
Broadcom shipped emergency fixes for three critical VMware flaws, including CVE-2026-59309 (CVSS 9.8), which lets any attacker with network access to vCenter by
- CVEN-able N-central auth bypass, incomplete patch of CVE-2026-18556
N-able N-central authentication bypass and account takeover. The first fix (CVE-2026-18556) was incomplete. Actively exploited. CISA added it to KEV on 3 August
- GuideGreenfield CIAM: how to ship the first version in 8 weeks
A practical 8-week plan to ship the first version of a customer identity system for a new product: what to build, what to defer, build-versus-buy, and the pitfa
- CVESailPoint IdentityIQ directory traversal, CVSS 10.0
IdentityIQ exposed protected static content through improper access control and directory traversal. CVSS 10.0. Disclosed December 2024. e-fixes for 8.2p8, 8.3p