N-able patches critical N-central zero-day exploited in the wild (CVE-2026-86218)

N-able patches critical N-central zero-day exploited in the wild (CVE-2026-86218)
N-able released an emergency hotfix for CVE-2026-86218, a critical pre-authenticated remote code execution flaw in N-central used by MSPs. The company urged on-premises customers to upgrade immediately, while reports also suggested the vulnerability may have been exploited in the wild. #N-able #N-central #CVE-2026-86218 #Huntress

Keypoints

  • N-able patched CVE-2026-86218 with Hotfix 4 for N-central 2026.3.
  • The flaw could allow pre-authenticated remote code execution on the N-central server.
  • N-able told on-premises customers to upgrade immediately to version 2026.3.1.14.
  • A private customer notice said the issue was being exploited in the wild and treated it as a zero-day.
  • Huntress also warned about CVE-2026-86206 and CVE-2026-86207 affecting N-central access.

Read More: https://www.helpnetsecurity.com/2026/09/07/n-able-n-central-hotfix-cve-2026-86218/