N-able released an emergency hotfix for CVE-2026-86218, a critical pre-authenticated remote code execution flaw in N-central used by MSPs. The company urged on-premises customers to upgrade immediately, while reports also suggested the vulnerability may have been exploited in the wild. #N-able #N-central #CVE-2026-86218 #Huntress
Keypoints
- N-able patched CVE-2026-86218 with Hotfix 4 for N-central 2026.3.
- The flaw could allow pre-authenticated remote code execution on the N-central server.
- N-able told on-premises customers to upgrade immediately to version 2026.3.1.14.
- A private customer notice said the issue was being exploited in the wild and treated it as a zero-day.
- Huntress also warned about CVE-2026-86206 and CVE-2026-86207 affecting N-central access.
Read More: https://www.helpnetsecurity.com/2026/09/07/n-able-n-central-hotfix-cve-2026-86218/