N-able has issued an emergency hotfix for CVE-2026-86218, a maximum-severity RCE flaw in its N-central RMM platform that could let unauthenticated attackers run malicious code on exposed systems. Shadowserver reports nearly 1,500 internet-facing N-central servers, while Huntress says on-premises customers should move to N-central 2026.3 HF4 immediately because HF3 remains vulnerable. #Ncentral #CVE202686218 #Nable #ShadowserverFoundation #Huntress
Keypoints
- N-able patched CVE-2026-86218 with N-central 2026.3 Hotfix 4.
- The flaw allows low-complexity remote code execution without privileges.
- Huntress warned that CVE-2026-86218 may be a potential zero-day.
- Two additional flaws, CVE-2026-86206 and CVE-2026-86207, were also fixed.
- Shadowserver found nearly 1,500 N-central servers exposed online.