N-able released N-central 2026.3 Hotfix 4 to remediate CVE-2026-86218, a maximum-severity pre-authentication remote-code-execution vulnerability in its on-premises N-central remote monitoring and management platform. An unauthenticated attacker can exploit internet-exposed, unpatched instances with low complexity to execute malicious code; deployments on Hotfix 3 remain vulnerable, and N-able urged immediate installation of Hotfix 4.
N-able had not confirmed exploitation in production at the time of reporting, but Huntress identified a compromised customer environment and could not determine whether CVE-2026-86218 or separately patched high-severity flaws CVE-2026-86206 and CVE-2026-86207 caused the intrusion because relevant logs had rotated. Shadowserver identified nearly 1,500 internet-exposed N-central servers, concentrated in the United States and Europe, leaving a substantial potential attack surface.

See affected versions and whether adversaries are exploiting it.
16 events from the most recent confirmed update back to the earliest known activity.
Stephen Fewer submitted a Metasploit module demonstrating unauthenticated RCE against N-able N-central 2026.3.1.13 via a multipart race condition and the unauthenticated LogRetrieval CGI endpoint. The proof of concept obtained a reverse TCP Meterpreter session as the Linux user "nable"; the endpoint remains exposed until N-central is restarted.
The Canadian Centre for Cyber Security issued advisory AV26-885 warning that N-able N-central versions before 2026.3.1.14 are affected by CVE-2026-86218. It urged users and administrators to follow N-able guidance and apply available updates, including N-central 2026.3 Hotfix 4.
N-able released N-central 2026.3 Hotfix 4 to remediate CVE-2026-86218, a pre-authentication, low-complexity remote-code-execution vulnerability affecting on-premises N-central deployments. The company urged customers to apply the hotfix immediately, warning that systems on Hotfix 3 remain vulnerable.
CVE-2026-86206 was published as a medium-severity vulnerability in N-able N-central's internal API access-control filter that permits unauthorized network access to internal APIs. N-able fixed it in N-central 2026.3 HF3 and 2026.4; Michael Tigges of Huntress and Rashmi Harish of Rapid7 were credited as finders.
CVE-2026-86207 was published as a high-severity authentication-bypass flaw affecting N-able N-central versions before 2026.3.1.13 (earlier than 2026.3 HF 3). The flaw can provide unauthorized access to internal-only APIs and was credited to researchers from Huntress and Rapid7.
While investigating a fully patched N-central environment compromised after earlier fixes, Huntress reproduced an exploit chain involving CVE-2026-86206 and CVE-2026-86207. The two vulnerabilities could be chained to compromise N-central despite the earlier hotfixes.
Huntress observed attacks targeting N-central's underlying API and appliance logs beginning on September 4, 2026. Limited historical appliance logging prevented it from attributing the activity to CVE-2026-86218 or ruling out exploitation of other vulnerabilities.
During the same weekend as the CVE-2026-86218 hotfix, N-able also patched high-severity vulnerabilities CVE-2026-86206 and CVE-2026-86207. The flaws could allow attackers to bypass authentication and gain full access to a vulnerable N-central platform.
CISA added CVE-2026-18556 and CVE-2026-18577, high-severity N-able authentication-bypass vulnerabilities that had been exploited earlier in 2026, to its Known Exploited Vulnerabilities catalog. N-able had issued fixes for them in Hotfix 1 and Hotfix 2 earlier that month.
N-able detected an intrusion in which attackers exploited an authentication bypass to obtain administrative access to N-central servers. The attackers used the Take Control feature to access managed endpoints and registered Cloudflare Tunnel services for persistence; N-able said a limited number of customers were affected.
N-able patched the N-central vulnerabilities CVE-2025-8875 and CVE-2025-8876 while they were under active exploitation. Shadowserver subsequently identified 880 N-central servers that remained vulnerable to attacks targeting those flaws.
Italy's CSIRT advisory described CVE-2026-86218 as resulting from insufficient sanitization of externally supplied code-based directives. An unauthenticated attacker can use crafted HTTP/HTTPS requests to inject directives into static files on an exposed N-central server, which execute when processed and enable arbitrary code execution.
CISA added the maximum-severity N-able N-central vulnerability CVE-2026-86218 to its Known Exploited Vulnerabilities catalog. The pre-authentication remote-code-execution flaw was patched in N-central 2026.3 Hotfix 4, and federal civilian agencies were directed to remediate it by September 11, 2026.
Shadowserver Foundation tracked nearly 1,500 N-central servers exposed to the internet, with most located in the United States and Europe. The exposed deployments represented a substantial potential attack surface for the newly patched vulnerabilities.
Huntress observed a compromised N-central instance in a customer's patched production environment. Because relevant server logs had rotated, it could not determine whether CVE-2026-86218, CVE-2026-86206, or CVE-2026-86207 caused the compromise.
An urgent N-able customer notice characterized CVE-2026-86218 as a zero-day observed being exploited in the wild, affecting hosted and on-premises N-central deployments across the Americas, APAC, and Europe. This conflicted with N-able's public advisory, which said it had no confirmed evidence of production exploitation.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
29 references tracked. Mallory keeps watching after this page renders.
cert.az
Open sourcegithub.com
Open sourcecryptika.com
Open sourcecybersecuritynews.com
Open sourcedocumentation.n-able.com
Open sourcecve.org
Open sourcecve.org
Open sourceme.n-able.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.