N-able has released an emergency fix for a critical security flaw in its N-central endpoint management platform that could let attackers break into servers without credentials. The zero-day is tracked as CVE-2026-86218 and rated 10.0, affecting on-premises N-central instances; hosted customers were patched server-side. N-able says admins should install hotfix 2026.3 HF4, review logs for exploit scans from 23.234.64.0/18, and check for unknown newly created user accounts. The hotfix supersedes earlier fixes for CVE-2026-86206 and CVE-2026-86207, which Huntress said may have been chained in attacks starting September 4, 2026.
Why it matters: Organizations that run N-central on-premises could have their remote management server taken over, which can give attackers a path into many managed systems. This is urgent: patch immediately, review logs, and investigate for rogue admin accounts or signs of scanning and compromise.
info@thehackernews.com (The Hacker News)
2026.09.09
97% relevant
This is the same underlying event: active exploitation of N-able N-central pre-authentication RCE CVE-2026-86218. The article appears to be another report on the in-the-wild exploitation and patching of that zero-day affecting N-central servers.
Ionut Arghire
2026.09.08
100% relevant
This article establishes a distinct new story because it is the first tracked item here about CVE-2026-86218 in N-able N-central, including the vendor's emergency patch guidance and indicators for defenders.
← Back to all stories