< Back to all clusters
[TECHNOLOGY] · United States, Germany · 8 sources

started · updated

N-able issues emergency hotfix for critical N-central RCE vulnerability

N-able has released an emergency hotfix (build 2026. 3. 1. 14) to address a maximum-severity remote code execution (RCE) vulnerability, tracked as CVE-2026-86218, in its N-central remote monitoring and management platform. The flaw, which carries a CVSS score of 10.0, allows unauthenticated attackers to execute arbitrary code via static code injection.

There are conflicting reports regarding active exploitation. N-able’s incident notice states the vulnerability has been observed being exploited in the wild, whereas its official release notes state there is no confirmation of exploitation in production environments. Cybersecurity firm Huntress has flagged the flaw as a potential zero-day and has observed exploitation attempts across multiple vulnerability waves affecting the platform.

This latest issue follows a series of critical vulnerabilities in N-central, including an authentication bypass chain (CVE-2026-86206 and CVE-2026-86207) disclosed on September 5. Because N-central is widely used by Managed Service Providers (MSPs), the vulnerability poses a significant supply chain risk, potentially allowing attackers to pivot from a single compromised instance to numerous downstream client networks.

N-able has already patched all hosted N-central instances. However, on-premises customers are urged to upgrade to the latest hotfix immediately to mitigate the risk. The Shadowserver Foundation is currently tracking approximately 1,500 exposed N-central servers online.

Entities

Cloudflare · Huntress · N-able · N-central · Shadowserver Foundation

Claims

What the coverage asserts, and how many sources carry each claim.