N-able patches CVSS 10.0 RCE flaw in N-central amid reports of active exploitation
N-able has released N-central 2026.3 Hotfix 4 (build 2026.3.1.14) to address CVE-2026-86218, a pre-authentication remote code execution vulnerability scoring 10.0 on the CVSS scale. The flaw affects self-hosted and N-able-hosted N-central deployments, and successful exploitation could grant attackers code execution on the RMM server without valid credentials. Security firm Huntress noted conflicting vendor communications — some suggesting active exploitation in the wild, while official release notes stopped short of confirming production incidents. Huntress also flagged that log rotation at an affected customer site prevented definitive attribution of a specific incident to this vulnerability. Two related but separate vulnerabilities, CVE-2026-86206 and CVE-2026-86207, were also disclosed; the earlier Hotfix 3 does not address CVE-2026-86218.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in