[CRITICAL] "N-able patches critical N-central zero-day exploited in the wild (CVE-2026-86218)"
criticalDetails
A critical pre-authentication remote code execution (RCE) vulnerability, CVE-2026-86218, has been discovered in N-able's N-central RMM solution. The flaw allows an attacker to execute code on the N-central server without needing to authenticate. At least one report indicates the vulnerability has been exploited in the wild as a zero-day.
Affected Systems
All on-premises N-able N-central builds below 2026.3.1.14.
Potential Impact
Successful exploitation could lead to a complete compromise of the N-central server, enabling attackers to control the remote monitoring and management infrastructure. This could provide downstream access to the networks of all managed service provider (MSP) clients, leading to widespread data breaches and ransomware deployment.
Mitigations
Immediately apply Hotfix 4 for N-central 2026.3 to update to build version 2026.3.1.14 or later.