Critical RCE Flaw in N-able N-central Puts All Managed Endpoints at Risk
A critical pre-authentication remote code execution vulnerability, CVE-2026-86218, has been discovered in N-able N-central, a widely used remote monitoring and management platform, affecting all versions below 2026.3.1.14. The flaw carries a maximum CVSS 4.0 score of 10.0, requiring no privileges or user interaction, and allows attackers to execute code on the console over the network. Because RMM platforms control endpoints, servers, and networks across entire customer bases, a single compromise can give attackers administrative reach over hundreds of downstream systems. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on 8 September 2026 with a federal remediation deadline of 11 September 2026, and active exploitation in the wild has been confirmed. Self-hosted deployments must manually upgrade to N-central 2026.3 Hotfix 4, and administrators are advised to audit for signs of prior compromise rather than relying on patching alone.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in