ZeroHour
Help Net Securitypublished ()ingested @helpnetsecurity

N-able patches critical N-central zero-day exploited in the wild (CVE-2026-86218)

criticalExploit / PoC exploited in the wildimportance 84CVE-2026-86218CVE-2026-86206CVE-2026-86207
AI summary · glm-5.3-flash

N-able shipped an emergency hotfix for CVE-2026-86218, a pre-auth RCE zero-day in N-central RMM observed exploited in the wild.

N-able released Hotfix 4 for N-central 2026.3 on September 5 (build 2026.3.1.14), fixing CVE-2026-86218, a critical pre-authenticated remote code execution flaw in its RMM platform popular with MSPs. A private customer notice marked urgent said the zero-day 'has been observed being exploited in the wild,' while the public advisory said there were no confirmed production exploits. Huntress also flagged two high-severity vulnerabilities, CVE-2026-86206 and CVE-2026-86207, which allow authentication bypass and unrestricted access; they were patched the same weekend and were discovered by Rapid7's Stephen Fewer. N-able advised auditing N-central user accounts for unexpected users.

  • CVE-2026-86218: critical pre-auth RCE in N-central; hotfix 2026.3.1.14 released September 5
  • Private notice says exploited in the wild; public advisory claims no confirmed production exploitation
  • Both hosted and on-prem N-central deployments affected across Americas, APAC, and Europe
  • Auth bypass flaws CVE-2026-86206 and CVE-2026-86207 found by Rapid7, patched same weekend
  • Huntress customer saw a compromised patched N-central server; logs had already rotated
ProductsN-central
OrganizationsStephen Fewer

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-86206
Access Control Filter Bypass in N-able N-central Exposes Internal APIs

N-able N-central contains a flaw in the access-control filter that protects its internal API (CWE-791, incomplete filtering), allowing requests to bypass the filter and reach internal APIs without authorization. The issue is exploitable over the network with no privileges and no user interaction, per the CVSS 4.0 vector (AV:N/PR:N/UI:N). An attacker gains unauthorized, low-impact access to internal APIs (VC:L); the vector indicates no integrity or availability impact and no evidence of code execution from this flaw. Any organization running an affected N-central release — a remote monitoring and management (RMM) platform operated by managed service providers — is affected, and the fix is available in N-central 2026.3 HF3 and 2026.4. The flaw is not on the CISA KEV list and has no known public PoC or confirmed in-the-wild exploitation, though it was disclosed in the same patching cycle as actively exploited N-central unauthenticated RCE flaws.

Do: Upgrade N-central to 2026.3 HF3 or 2026.4 as soon as practical. While patching, limit direct internet exposure of the N-central API and check logs for unauthenticated requests to internal API endpoints. Note this release cycle included several recent N-central hotfixes, including an actively exploited unauthenticated RCE, so ensure all outstanding patches are applied.

6.9<1%
  • N-able N-central Releases prior to 2026.3 HF3; fixed in 2026.3 HF3 and 2026.4
large≈ tens of thousands of N-central server deployments (MSP RMM installs), with only the internet-exposed subset directly reachable
CVE-2026-86207
Authentication bypass in N-able N-central internal APIs before 2026.3 HF 3

CVE-2026-86207 is an authentication bypass (CWE-305) in N-able's N-central remote monitoring and management (RMM) platform that allows unauthorized access to APIs that are supposed to be internal-only. It is triggered over the network by sending requests to these internal API endpoints under specific conditions (the CVSS vector indicates some attack prerequisites and a low-privilege foothold are required). An attacker who exploits it gains highly privileged access to the N-central server's data and functions, with high impact on confidentiality, integrity and availability of the server itself. Organizations running any N-central release before version 2026.3 Hotfix 3 are affected — primarily managed service providers hosting N-central for their own operations. There is no public proof of concept, the flaw is not in CISA's KEV catalog, and EPSS puts 30-day exploitation risk at just 0.7%; note that the recent news headlines about actively exploited 'unauthenticated RCE' flaws in N-central describe separate vulnerabilities in the same product, which is why multiple hotfixes have shipped in quick succession.

Do: Upgrade all N-central servers to version 2026.3 HF 3 or later, or apply the vendor's hotfix to your current release. Restrict network access to the N-central web/API interface to trusted networks and review logs for unexpected access to internal API endpoints. Given the recent string of N-central fixes — including the separately exploited pre-auth RCE — verify that every recent hotfix has been applied to each N-central instance you operate.

7.7<1%
  • N-able N-central all versions before 2026.3 HF 3 (Hotfix 3)
moderate≈ several thousand to low tens of thousands of N-central server deployments (typically one internet-exposed server per MSP)
CVE-2026-86218
Pre-Auth Static Code Injection RCE in N-able N-central (Exploited in the Wild)

CVE-2026-86218 is a static code injection flaw (CWE-96) in N-able's N-central on-premises remote monitoring and management (RMM) platform, carrying a maximum CVSS 4.0 score of 10.0. An unauthenticated, remote attacker triggers it by sending crafted network input to the N-central server that is improperly neutralized and persisted into application-managed code, which the server then executes — no privileges (PR:N) or user interaction (UI:N) are required. Successful exploitation yields full server compromise with high impact on confidentiality, integrity, and availability, and because N-central acts as the management hub for downstream customer endpoints, compromise can expose the entire managed estate. Any organization running an affected N-central release (before 2026.3.1.14) — primarily MSPs and corporate IT departments using N-able RMM — is affected. The flaw is confirmed exploited in the wild: N-able patched it as a zero-day, CISA added it to the KEV catalog on 2026-09-08, and it is the fourth N-central hotfix in five weeks, though no public PoC is known and ransomware use is unknown.

Do: Upgrade N-central to 2026.3.1.14 or later (or apply N-able's hotfix) immediately, as the flaw is in CISA's KEV catalog and BOD 26-04 timelines apply to federal stakeholders. Until patched, remove direct internet exposure of the N-central server (restrict to VPN/management networks via firewall allowlists) since no authentication is needed for exploitation. Because in-the-wild exploitation is confirmed, review internet-facing N-central servers for indicators of compromise such as unexpected processes, unusual child processes of the web service, and new or suspicious accounts.

10.0<1% KEV PoC
  • N-able N-central before 2026.3.1.14
large≈ tens of thousands of deployed/internet-exposed N-central servers (order of magnitude ~10k+), each managing many downstream customer endpoints
Full article377 words · extracted from helpnetsecurity.com · click to collapse

N-able released an emergency hotfix for CVE-2026-86218, a remote code execution (RCE) flaw affecting N-central, its remote monitoring and management (RMM) solution popular with managed service providers (MSPs).

N-central hotfix CVE-2026-86218

In its release notes, N-able described CVE-2026-86218 as a “critical-CVSS-rated vulnerability that could allow for pre-authenticated remote code execution on the N-central server.”

N-able addressed the flaw on September 5 by releasing Hotfix 4 for N-central 2026.3, bringing the build to version 2026.3.1.14.

“Customers running on-premises N-central deployments should upgrade to N-central 2026.3 HF4 immediately to protect their environment,” the company added.

“This vulnerability was responsibly disclosed by a third party through our security disclosure program. At this time, we have no confirmations that this vulnerability has been exploited in production environments, but unpatched systems remain at risk,” the company noted.

In a separate notice sent directly to customers, marked as urgent and calling for the hotfix to be applied immediately, N-able said CVE-2026-86218 “has been observed being exploited in the wild” and called it a zero-day, contradicting the claims in its public advisory.

The notice listed both hosted and on-premises N-central deployments as impacted, spanning the Americas, APAC, and Europe.

Cybersecurity firm Huntress also flagged CVE-2026-86218 as a potential zero-day, alongside two high-severity vulnerabilities, CVE-2026-86206 and CVE-2026-86207, which N-able patched over the weekend and which can allow attackers to bypass authentication and gain unrestricted access to the N-central platform.

The firm says it learned of the flaw through a Discord post from an N-able employee in the MSPGeek community, ahead of N-able’s own public hotfix announcement.

“In our 9/5/26 update, we had said we could not rule out whether the two previous vulnerabilities released (CVE-2026-86206 and CVE-2026-86207) were the ones that were exploited in the instance seen in the patched production environment of one of our customers. Because logs on the compromised N-central server had already rotated, we are also unable to say whether this new CVE was the vulnerability exploited in that case,” Huntress explained.

“As a precaution, we recommend auditing your N-central user accounts to ensure that there are no unexpected users,” N-able advised.

UPDATE (September 8, 2026, 09:55 a.m. ET):

CVE-2026-86206 and CVE-2026-86207 were discovered by Stephen Fewer, Senior Principal Security Researcher at Rapid7. He now published a technical analysis of both.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/09/07/n-able-n-central-hotfix-cve-2026-86218/