N-able Releases Hotfix for Critical Remote Code Execution Vulnerability

Used in attacksCriticalInfosecurity Magazine·

At a glance

Severity
Critical
Used in attacks
Yes, 1 of 1 flaw named
Flaws named
CVE-2026-86218
Reported by
1 outlet

Managed IT software provider N-able has released a new hotfix that includes a patch for a critical remote code execution (RCE) vulnerability.

CVE-2026-86218 is a critical pre-authentication RCE flaw in N-central, N-able’s remote monitoring and management platform. It was disclosed by the software provider on September 6 and was allocated a maximum-severity rating (CVSS) of 10.

The vulnerability affects N-central versions before 2026.3.1.14 and can allow an unauthenticated attacker to execute code on the N-central server.

N-able has not publicly disclosed the affected component or exploitation method. It said it has found no evidence that CVE-2026-86218 has been exploited in production environments.

Meanwhile, the software provider released a patch for the vulnerability in its N-central 2026.3 Hotfix 4, which brings the build to 2026.3.1.14.

This is the latest of five vulnerabilities affecting N-able products in a few weeks.

CVE-2026-18556 and CVE-2026-18577 are high-severity authentication bypasses that were found to be exploited earlier in 2026 – and added to the US Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities (KEV) catalog in August.

Patches for those two vulnerabilities were included in N-able’s HF1 and HF2 hotfixes, published on August 2 and 6.

CVE-2026-86207 is a high-severity authentication bypass affecting internal only APIs and CVE-2026-86206 is a high-severity access-control filter bypass exposing internal APIs. They were both patched in N-able’s HF3 hotfix on September 5.

Image credits: Cristi Dangeorge / Shutterstock.com

Reproduced in full under licence from Infosecurity Magazine. © Infosecurity Magazine.

Vulnerabilities referenced

  • CVE-2026-862189.8Critical

    N-able N-central

    N-able N-central contains a static code injection vulnerability that could allow for pre-authentication remote code execution.

    Used in attacks

    Added to CISA's list 2026-09-08 · Patch or advisory available

    Full record →

Coverage

One outlet has carried this so far.

  1. Infosecurity MagazineEstablished SourceFirst reported

    2026-09-07 12:45 UTC

Related stories