ZeroHour
Cyber Security Newspublished ()ingested Guru Baran1
Part of a story covered by 5 sources: “N-able N-central pre-auth RCE (CVE-2026-86218) exploited in the wild and added to CISA KEV; Akamai details StyleSmuggler, Canada flags another Adobe Commerce flaw” — merged summary and timeline →

CISA Warns of N-able N-central RCE Vulnerability Exploited in the Wild

criticalExploit / PoC exploited in the wildimportance 84CVE-2026-86218CVE-2026-86206CVE-2026-86207
AI summary · glm-5.3-flash

CISA added CVE-2026-86218, a CVSS 10.0 unauthenticated RCE in N-able N-central RMM, to its KEV catalog; on-premises admins must patch to 2026.3.1.14.

CISA added CVE-2026-86218, a CVSS 10.0 static code injection (CWE-96) enabling unauthenticated RCE in N-able N-central, to the Known Exploited Vulnerabilities catalog on September 8, 2026. The flaw affects all on-premises builds before 2026.3.1.14 across the 2025.4 through 2026.3 release lines; N-able shipped Hotfix 4 for 2026.3 on September 5-6, 2026. Huntress research indicates at least one customer's N-central instance was compromised on September 4, and federal civilian agencies must mitigate by September 11 under BOD 26-04. Hosted environments were patched server-side, but a compromised RMM server can serve as a single point of entry into entire MSP client bases.

  • CVE-2026-86218 (CVSS 10.0, CWE-96) enables unauthenticated RCE on exposed N-central servers
  • Added to CISA KEV September 8; BOD 26-04 gives federal agencies until September 11 to mitigate
  • Affects on-premises builds before 2026.3.1.14 across the 2025.4-2026.3 release lines
  • Huntress reported a customer compromise on September 4, two days before the hotfix shipped
  • Fourth N-able emergency hotfix in five weeks, after CVE-2026-86206 and CVE-2026-86207
VendorsN-able
ProductsN-central
OrganizationsCISAHuntress

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-86206
Access Control Filter Bypass in N-able N-central Exposes Internal APIs

N-able N-central contains a flaw in the access-control filter that protects its internal API (CWE-791, incomplete filtering), allowing requests to bypass the filter and reach internal APIs without authorization. The issue is exploitable over the network with no privileges and no user interaction, per the CVSS 4.0 vector (AV:N/PR:N/UI:N). An attacker gains unauthorized, low-impact access to internal APIs (VC:L); the vector indicates no integrity or availability impact and no evidence of code execution from this flaw. Any organization running an affected N-central release — a remote monitoring and management (RMM) platform operated by managed service providers — is affected, and the fix is available in N-central 2026.3 HF3 and 2026.4. The flaw is not on the CISA KEV list and has no known public PoC or confirmed in-the-wild exploitation, though it was disclosed in the same patching cycle as actively exploited N-central unauthenticated RCE flaws.

Do: Upgrade N-central to 2026.3 HF3 or 2026.4 as soon as practical. While patching, limit direct internet exposure of the N-central API and check logs for unauthenticated requests to internal API endpoints. Note this release cycle included several recent N-central hotfixes, including an actively exploited unauthenticated RCE, so ensure all outstanding patches are applied.

6.9<1%
  • N-able N-central Releases prior to 2026.3 HF3; fixed in 2026.3 HF3 and 2026.4
large≈ tens of thousands of N-central server deployments (MSP RMM installs), with only the internet-exposed subset directly reachable
CVE-2026-86207
Authentication bypass in N-able N-central internal APIs before 2026.3 HF 3

CVE-2026-86207 is an authentication bypass (CWE-305) in N-able's N-central remote monitoring and management (RMM) platform that allows unauthorized access to APIs that are supposed to be internal-only. It is triggered over the network by sending requests to these internal API endpoints under specific conditions (the CVSS vector indicates some attack prerequisites and a low-privilege foothold are required). An attacker who exploits it gains highly privileged access to the N-central server's data and functions, with high impact on confidentiality, integrity and availability of the server itself. Organizations running any N-central release before version 2026.3 Hotfix 3 are affected — primarily managed service providers hosting N-central for their own operations. There is no public proof of concept, the flaw is not in CISA's KEV catalog, and EPSS puts 30-day exploitation risk at just 0.7%; note that the recent news headlines about actively exploited 'unauthenticated RCE' flaws in N-central describe separate vulnerabilities in the same product, which is why multiple hotfixes have shipped in quick succession.

Do: Upgrade all N-central servers to version 2026.3 HF 3 or later, or apply the vendor's hotfix to your current release. Restrict network access to the N-central web/API interface to trusted networks and review logs for unexpected access to internal API endpoints. Given the recent string of N-central fixes — including the separately exploited pre-auth RCE — verify that every recent hotfix has been applied to each N-central instance you operate.

7.7<1%
  • N-able N-central all versions before 2026.3 HF 3 (Hotfix 3)
moderate≈ several thousand to low tens of thousands of N-central server deployments (typically one internet-exposed server per MSP)
CVE-2026-86218
Pre-Auth Static Code Injection RCE in N-able N-central (Exploited in the Wild)

CVE-2026-86218 is a static code injection flaw (CWE-96) in N-able's N-central on-premises remote monitoring and management (RMM) platform, carrying a maximum CVSS 4.0 score of 10.0. An unauthenticated, remote attacker triggers it by sending crafted network input to the N-central server that is improperly neutralized and persisted into application-managed code, which the server then executes — no privileges (PR:N) or user interaction (UI:N) are required. Successful exploitation yields full server compromise with high impact on confidentiality, integrity, and availability, and because N-central acts as the management hub for downstream customer endpoints, compromise can expose the entire managed estate. Any organization running an affected N-central release (before 2026.3.1.14) — primarily MSPs and corporate IT departments using N-able RMM — is affected. The flaw is confirmed exploited in the wild: N-able patched it as a zero-day, CISA added it to the KEV catalog on 2026-09-08, and it is the fourth N-central hotfix in five weeks, though no public PoC is known and ransomware use is unknown.

Do: Upgrade N-central to 2026.3.1.14 or later (or apply N-able's hotfix) immediately, as the flaw is in CISA's KEV catalog and BOD 26-04 timelines apply to federal stakeholders. Until patched, remove direct internet exposure of the N-central server (restrict to VPN/management networks via firewall allowlists) since no authentication is needed for exploitation. Because in-the-wild exploitation is confirmed, review internet-facing N-central servers for indicators of compromise such as unexpected processes, unusual child processes of the web service, and new or suspicious accounts.

10.0<1% KEV PoC
  • N-able N-central before 2026.3.1.14
large≈ tens of thousands of deployed/internet-exposed N-central servers (order of magnitude ~10k+), each managing many downstream customer endpoints
Full article501 words · extracted from cybersecuritynews.com · click to collapse

The Cybersecurity and Infrastructure Security Agency has added a maximum-severity flaw in N-able’s N-central remote monitoring and management platform to its Known Exploited Vulnerabilities catalog, confirming that attackers are actively abusing the bug against real-world targets.

The vulnerability, tracked as CVE-2026-86218, carries a perfect CVSS score of 10.0 and allows unauthenticated remote code execution, making it one of the most dangerous flaws to hit the managed service provider ecosystem this year.

CISA classifies CVE-2026-86218 as a static code injection vulnerability tied to CWE-96, meaning attackers can inject malicious directives into statically saved, executable code on the N-central server.

N-able N-central RCE Vulnerability

Because the flaw requires no authentication or user interaction, any threat actor with network access to an exposed N-central instance could run arbitrary commands, giving them a foothold not just into the platform itself but into every downstream endpoint an MSP manages through it.

The bug was reported to N-able through the company’s responsible disclosure program and affects all on-premises N-central builds prior to version 2026.3.1.14, spanning the 2025.4, 2026.1, 2026.2, and 2026.3 release lines, including systems that had already applied earlier hotfixes in the same release cycle.

N-able shipped Hotfix 4 for N-central 2026.3 on September 5-6, 2026, bringing on-premises deployments to build 2026.3.1.14. This marked the fourth emergency hotfix the company issued within five weeks, following earlier fixes for separate authentication bypass and RCE issues tracked as CVE-2026-86206 and CVE-2026-86207.

Hosted N-central customers did not need to take action since N-able patched those environments server-side, but on-premises administrators were urged to upgrade immediately.

While N-able initially stated it had no confirmation of exploitation in production environments, CISA’s KEV listing and independent research from Huntress indicate otherwise, with at least one customer’s N-central instance reportedly compromised on September 4, two days before the patch shipped. CISA added the flaw to its catalog on September 8, 2026.

Under Binding Operational Directive 26-04, federal civilian agencies running affected N-central instances have until September 11, 2026, to apply mitigations, and CISA is requiring forensic triage on any system found exposed prior to patching. The directive also instructs agencies to follow BOD 26-04 guidance for cloud services or discontinue use of the product entirely if mitigations cannot be applied in time.

Given N-central’s widespread use among MSPs managing thousands of downstream client networks, security teams should treat this as an urgent, organization-wide priority rather than a routine patch cycle.

Administrators should upgrade on-premises instances to 2026.3.1.14 immediately, audit internet exposure of their N-central servers, and review logs for signs of compromise dating back to early September, since a compromised RMM server can serve as a single point of entry into an entire client base.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

Guru Baranhttps://cybersecuritynews.com

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/n-able-n-central-rce/