ZeroHour
Story · 1 source · 1 articlefirst updated ()

N-able Rushes Hotfix for CVSS 10 Pre-Auth RCE in N-central as CVE-2026-86218 Is Exploited in the Wild and Added to CISA KEV

What's new: First merged summary for this story. Between September 7 and September 9, 2026, the situation escalated significantly: N-able's stance shifted from 'no evidence of production exploitation' to confirmed in-the-wild zero-day exploitation; CISA added CVE-2026-86218 to the KEV catalog on September 8 with a September 11 BOD 26-04 mitigation deadline; the Canadian Centre for Cyber Security issued…
Merged summary · glm-5.3 · rewritten as coverage arrives

N-able shipped N-central 2026.3 Hotfix 4 (build 2026.3.1.14) for CVE-2026-86218, a CVSS 10.0 pre-authentication static code injection RCE affecting on-premises deployments; after initially reporting no evidence of exploitation, the vendor confirmed…

CVE-2026-86218 is a maximum-severity (CVSS 10.0) pre-authentication remote code execution flaw caused by static code injection (CWE-96) in N-able's N-central remote monitoring and management platform, which is widely used by MSPs. It affects all on-premises builds before 2026.3.1.14 across the 2025.4 through 2026.3 release lines and is fixed in N-central 2026.3 Hotfix 4 (build 2026.3.1.14), released September 5-6, 2026; hosted environments were already patched server-side. Disclosure initially came September 6-7 with N-able stating it had found no evidence of exploitation in production, but by September 8 the vendor confirmed the flaw is being exploited in the wild as a zero-day. SecurityWeek reported scanning/exploitation attempts from the IP range 23.234.64.0/18 starting September 4, and Huntress is investigating a September 4 compromise of a fully patched customer N-central environment, unable yet to confirm which flaw was used. CISA added the CVE to its Known Exploited Vulnerabilities catalog on September 8, 2026, and under BOD 26-04 federal civilian agencies must mitigate by September 11, 2026; the Canadian Centre for Cyber Security issued advisory AV26-885 urging immediate patching. Hotfix 4 supersedes Hotfix 3 (September 5), which fixed Rapid7-disclosed chained flaws CVE-2026-86206 (CWE-791, CVSSv4 6.9) and CVE-2026-86207 (CWE-305, CVSSv4 7.7) that together let a remote unauthenticated attacker create a rogue System Administrator account by exploiting a disagreement between Envoy and Jetty proxies over the requested path and whether the client is local; Huntress observed these potentially chained in the wild. These follow August's KEV-listed N-central authentication bypasses CVE-2026-18556 and CVE-2026-18577 (the latter also Rapid7-disclosed), exploited after disclosure. Infosecurity counts CVE-2026-86218 as the fifth N-able vulnerability disclosed in weeks, while Cyber Security News calls it the fourth N-able emergency hotfix in five weeks. Admins are advised to apply the hotfix, audit logs, and remove unrecognized newly created user accounts, since a compromised RMM server can serve as a single point of entry into an MSP's entire client base.

  • CVE-2026-86218: CVSS 10.0 pre-authentication RCE via static code injection (CWE-96) in N-able N-central; affected component undisclosed.
  • Affected versions: all on-premises N-central builds before 2026.3.1.14 across the 2025.4-2026.3 release lines; fix is N-central 2026.3 Hotfix 4 (build 2026.3.1.14), released September 5-6, 2026; hosted environments patched server-side.
  • Exploitation status evolved: on September 7 N-able reported no evidence of production exploitation; by September 8 the vendor confirmed in-the-wild exploitation as a zero-day.
  • Scanning/exploitation attempts observed from IP range 23.234.64.0/18 beginning September 4, 2026.
  • CISA added CVE-2026-86218 to the KEV catalog on September 8, 2026; BOD 26-04 requires federal civilian agencies to mitigate by September 11, 2026.
  • Canadian Centre for Cyber Security advisory AV26-885 urges users and administrators to apply the hotfix promptly.
  • Huntress is investigating a September 4, 2026 compromise of a fully patched customer N-central production server and cannot yet confirm which flaw was used.
  • CVE-2026-86206 (CWE-791, CVSSv4 6.9) and CVE-2026-86207 (CWE-305, CVSSv4 7.7), disclosed by Rapid7 and fixed in Hotfix 3 on September 5, can be chained by an unauthenticated attacker to create a rogue System Administrator account; root…

Coverage timeline

  1. · 8d ago
    Infosecurity Magazine· 72
    N-able Releases Hotfix for Critical Remote Code Execution Vulnerability

    N-able shipped Hotfix 4 patching CVE-2026-86218, a CVSS 10.0 pre-authentication RCE in N-central, with no confirmed production exploitation yet.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-18556
Authentication Bypass (Alternate Path/Channel) in N-able N-central

N-able's N-central RMM platform contains an authentication bypass (CWE-288) in which an alternate path or channel allows requests to skip the normal authentication check. An unauthenticated attacker can trigger it by sending requests through that alternate path without valid credentials, gaining unauthorized access to the N-central management interface; because N-central is remote monitoring and management software run by managed service providers, such access can expose management functions across downstream customer environments. N-able N-central deployments are affected; the available data does not specify affected version ranges or fixed builds. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-08-04, confirming exploitation in the wild, with a high EPSS of 40.2% (99th percentile), no CVSS score yet, no public PoC, and undetermined ransomware use; related reporting describes a recent string of N-central hotfixes, including fixes for unauthenticated remote code execution.

Do: Apply N-able's hotfix for N-central immediately per the vendor's instructions, since the flaw is in CISA KEV and BOD 26-04 applies (for cloud-hosted N-central, apply mitigations per BOD 26-04 or discontinue use if mitigations are unavailable). Until patched, restrict internet exposure of the N-central server to trusted management networks and review authentication logs for unexpected access, following CISA's forensics triage guidance. Check the vendor advisory for the exact fixed build, as the available data does not list affected or fixed version numbers.

8.240% KEV
  • N-able N-central
largeon the order of tens of thousands of N-central server instances (estimate; exact counts not in available data)
CVE-2026-18577
Authentication Bypass and Account Takeover in N-able N-central (Incomplete Patch)

CVE-2026-18577 is an authentication bypass (CWE-288) in N-able's N-central RMM platform caused by an incomplete patch for the earlier vulnerability CVE-2026-18556. Because the original fix can be bypassed via an alternate path or channel, a remote, unauthenticated attacker needs no privileges or user interaction, though the attack requires meeting exploit-specific conditions (high attack complexity, CVSS 4.0: 8.2 High). Successful exploitation lets the attacker bypass authentication and take over N-central accounts, gaining high-impact access to the management console with limited direct effects on downstream services. All N-central versions through 2026.3.1 are affected. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2026-08-03, EPSS estimates a 54.1% chance of exploitation within 30 days (99th percentile), and news reports say attackers kept exploiting it even as N-able shipped successive hotfixes; ransomware use is currently unknown.

Do: Upgrade N-central to a fixed release or hotfix newer than 2026.3.1 following N-able's advisory — the vendor has issued multiple successive hotfixes for this and related N-central flaws, so verify you are on the latest build. Because the flaw is on CISA's KEV, federal and BOD 26-04-bound organizations must apply vendor mitigations promptly or discontinue use of the product if patching is unavailable. Limit internet exposure of N-central portals and review accounts for signs of takeover or unauthorized access.

8.254% KEV
  • N-able N-central all versions through 2026.3.1 (incomplete patch for CVE-2026-18556)
moderate≈1,000–10,000 internet-exposed N-central server instances (estimate from public internet scans; total on-prem deployments likely higher, with millions of…
CVE-2026-86206
Access Control Filter Bypass in N-able N-central Exposes Internal APIs

N-able N-central contains a flaw in the access-control filter that protects its internal API (CWE-791, incomplete filtering), allowing requests to bypass the filter and reach internal APIs without authorization. The issue is exploitable over the network with no privileges and no user interaction, per the CVSS 4.0 vector (AV:N/PR:N/UI:N). An attacker gains unauthorized, low-impact access to internal APIs (VC:L); the vector indicates no integrity or availability impact and no evidence of code execution from this flaw. Any organization running an affected N-central release — a remote monitoring and management (RMM) platform operated by managed service providers — is affected, and the fix is available in N-central 2026.3 HF3 and 2026.4. The flaw is not on the CISA KEV list and has no known public PoC or confirmed in-the-wild exploitation, though it was disclosed in the same patching cycle as actively exploited N-central unauthenticated RCE flaws.

Do: Upgrade N-central to 2026.3 HF3 or 2026.4 as soon as practical. While patching, limit direct internet exposure of the N-central API and check logs for unauthenticated requests to internal API endpoints. Note this release cycle included several recent N-central hotfixes, including an actively exploited unauthenticated RCE, so ensure all outstanding patches are applied.

6.9<1%
  • N-able N-central Releases prior to 2026.3 HF3; fixed in 2026.3 HF3 and 2026.4
large≈ tens of thousands of N-central server deployments (MSP RMM installs), with only the internet-exposed subset directly reachable
CVE-2026-86207
Authentication bypass in N-able N-central internal APIs before 2026.3 HF 3

CVE-2026-86207 is an authentication bypass (CWE-305) in N-able's N-central remote monitoring and management (RMM) platform that allows unauthorized access to APIs that are supposed to be internal-only. It is triggered over the network by sending requests to these internal API endpoints under specific conditions (the CVSS vector indicates some attack prerequisites and a low-privilege foothold are required). An attacker who exploits it gains highly privileged access to the N-central server's data and functions, with high impact on confidentiality, integrity and availability of the server itself. Organizations running any N-central release before version 2026.3 Hotfix 3 are affected — primarily managed service providers hosting N-central for their own operations. There is no public proof of concept, the flaw is not in CISA's KEV catalog, and EPSS puts 30-day exploitation risk at just 0.7%; note that the recent news headlines about actively exploited 'unauthenticated RCE' flaws in N-central describe separate vulnerabilities in the same product, which is why multiple hotfixes have shipped in quick succession.

Do: Upgrade all N-central servers to version 2026.3 HF 3 or later, or apply the vendor's hotfix to your current release. Restrict network access to the N-central web/API interface to trusted networks and review logs for unexpected access to internal API endpoints. Given the recent string of N-central fixes — including the separately exploited pre-auth RCE — verify that every recent hotfix has been applied to each N-central instance you operate.

7.7<1%
  • N-able N-central all versions before 2026.3 HF 3 (Hotfix 3)
moderate≈ several thousand to low tens of thousands of N-central server deployments (typically one internet-exposed server per MSP)
CVE-2026-86218
Pre-Auth Static Code Injection RCE in N-able N-central (Exploited in the Wild)

CVE-2026-86218 is a static code injection flaw (CWE-96) in N-able's N-central on-premises remote monitoring and management (RMM) platform, carrying a maximum CVSS 4.0 score of 10.0. An unauthenticated, remote attacker triggers it by sending crafted network input to the N-central server that is improperly neutralized and persisted into application-managed code, which the server then executes — no privileges (PR:N) or user interaction (UI:N) are required. Successful exploitation yields full server compromise with high impact on confidentiality, integrity, and availability, and because N-central acts as the management hub for downstream customer endpoints, compromise can expose the entire managed estate. Any organization running an affected N-central release (before 2026.3.1.14) — primarily MSPs and corporate IT departments using N-able RMM — is affected. The flaw is confirmed exploited in the wild: N-able patched it as a zero-day, CISA added it to the KEV catalog on 2026-09-08, and it is the fourth N-central hotfix in five weeks, though no public PoC is known and ransomware use is unknown.

Do: Upgrade N-central to 2026.3.1.14 or later (or apply N-able's hotfix) immediately, as the flaw is in CISA's KEV catalog and BOD 26-04 timelines apply to federal stakeholders. Until patched, remove direct internet exposure of the N-central server (restrict to VPN/management networks via firewall allowlists) since no authentication is needed for exploitation. Because in-the-wild exploitation is confirmed, review internet-facing N-central servers for indicators of compromise such as unexpected processes, unusual child processes of the web service, and new or suspicious accounts.

10.0<1% KEV PoC ×2
  • N-able N-central before 2026.3.1.14
large≈ tens of thousands of deployed/internet-exposed N-central servers (order of magnitude ~10k+), each managing many downstream customer endpoints