Critical N-able N-central Flaw Lets Attackers Bypass Auth and Execute Code

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has raised the alarm over a severe unpatched vulnerability in N-able N-central that enables remote code execution without any prior authentication. Tagged CVE-2026-86218, this flaw carries the maximum possible CVSS severity score of 10.0 and is already listed in CISA’s Known Exploited Vulnerabilities catalog. All Federal Civilian Executive Branch agencies have been mandated to apply the fix by September 11, 2026.

If exploited, the vulnerability allows a remote attacker to inject static code—without needing to log in—directly into N-central systems, giving them the power to execute arbitrary code. The patch for CVE-2026-86218 was released on September 5, 2026, as part of N-central 2026.3 Hotfix 4.

Active Exploitation & Related Flaws

Security firm Huntress stated on September 4, 2026 that a fully patched N-central environment had already been compromised, sparking investigations into whether CVE-2026-86218 was the culprit, or whether the breach leveraged two previously patched vulnerabilities: CVE-2026-86206 and CVE-2026-86207. Those two flaws, when chained together, allow an attacker to bypass authentication, then create a system administrator account under attacker control.

Rapid7 researcher Stephen Fewer discovered CVE-2026-86206 and CVE-2026-86207. Huntress notes that system logs didn’t clearly indicate which of the three vulnerabilities was used in the incident, partly due to limited historic logging capabilities in the product.

Vendor Response & Urgent Guidance

N-able has confirmed that CVE-2026-86218 is being exploited in the wild. In an alert labeled “urgent” sent to customers, the company said it is investigating the breach and has taken extra protective steps for its users’ environments, urging immediate application of the hotfix.

Both CISA and N-able emphasize that organizations running N-central should deploy Hotfix 4 from version 2026.3 without delay to address this issue.

The timeline here is tight: while the vulnerability was patched on September 5, the federal deadline to secure affected systems is September 11, 2026. Organizations operating N-able N-central should verify whether they’re running a vulnerable version and check whether Hotfix 4 has been applied.

This pre-authentication remote code execution exploit represents a major risk in the world of managed service products. N-able N-central is widely used by businesses and managed service providers (MSPs) to monitor and manage networks, making the impact of a successful exploit far-reaching. With three closely related critical vulnerabilities in play, system backups, rapid patching, and thorough audit logging become essential safeguards.