TechNewsReel
Live

N-able Issues Fourth N-central Hotfix for Critical CVSS 10.0 RCE Flaw

The update addresses a maximum-severity vulnerability that allows unauthenticated attackers to execute arbitrary code on management servers.

TechNewsReel Newsroom · September 7, 2026

N-able has released a critical security update for its N-central remote monitoring and management (RMM) platform to block a maximum-severity remote code execution (RCE) vulnerability. The flaw, tracked as CVE-2026-86218, allows unauthenticated attackers to execute arbitrary code on exposed N-central servers.

To mitigate the risk, N-able has issued Hotfix 4 (build 2026.3.1.14). This update is required for all on-premises installations running versions below this build, including those that recently applied Hotfix 3. The vulnerability has been assigned a CVSS v4 score of 10.0, the highest possible severity rating, reflecting the ease of exploitation and the total impact on the affected system.

A Pattern of Critical Flaws

This latest patch is the fourth hotfix released for the N-central platform in just five weeks. The platform has recently been plagued by a series of high-risk security gaps, including a previous authentication bypass vulnerability tracked as CVE-2026-18577. That earlier flaw allowed unauthenticated users to gain administrative access to the system, highlighting a volatile period for the software's security posture.

The Risk to Managed Service Providers

Because N-central is primarily used by managed service providers (MSPs) and IT teams to oversee vast networks of endpoints, a compromise of the central management server is a high-stakes event. The platform holds broad administrative access to managed networks, credentials, and endpoints across multiple client environments.

An RCE on the management server effectively turns the RMM tool into a delivery mechanism for a supply-chain attack. If an attacker gains control of the N-central server, they could potentially deploy malware, steal sensitive data, or execute commands across an MSP's entire client base simultaneously, bypassing traditional perimeter defenses at the endpoint level.

Next Steps for Administrators

Administrators are urged to verify their current build version and apply build 2026.3.1.14 immediately. While the core vulnerability is confirmed and patched, the broader security trend suggests that organizations using N-central should maintain a heightened state of monitoring for unusual activity on their management consoles. Further audits of the platform's exposure to the public internet are recommended to reduce the attack surface for similar unauthenticated flaws.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.