N-able N-central CVE-2026-86218: CVSS 10.0, patch HF4
A pre-auth RCE rated CVSS 10.0 hits N-able N-central. Build 2026.3.1.14 fixes it. If an MSP runs your network, ask them today which build they are on.
N-able shipped an emergency hotfix for N-central today. CVE-2026-86218 is a CVSS 10.0 pre-authentication remote code execution flaw in the N-central server. No credentials, no user interaction, no clicking anything. The fix is build 2026.3.1.14, shipped as 2026.3 Hotfix 4. Every release before it is affected, going back through 2026.2, 2026.1, and 2025.4.
Most small businesses have never heard of N-central and are still exposed to it, because it is the console their IT provider uses to reach every machine they manage.
What actually happened
The bug is classed as CWE-96, static code injection — attacker-controlled input lands somewhere the server later evaluates as code. The published CVSS 4.0 vector is AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H. The trailing SC:H/SI:H/SA:H is the part to read twice: the scored impact does not stop at the N-central server. It extends to what sits behind it.
N-able says the flaw came in through its responsible disclosure program and that it has no confirmations of exploitation in production so far. That is genuinely better news than the alternative, and it is also the shortest-lived kind of good news there is. Cloud-hosted N-central instances were patched by N-able with no customer action. On-premises deployments are the customer's problem, and N-able's wording is unambiguous: upgrade immediately.
This is the third pre-auth problem in this product in roughly five weeks. We covered CVE-2026-18577, an authentication bypass that Rapid7 saw exploited in the wild, and then the follow-up hotfix when the first patch was not enough. A pattern that persistent is not bad luck.
Why your MSP's console matters for your business
An RMM console is the most privileged thing touching your network, and it is the one thing you almost certainly do not own. It has an agent with SYSTEM rights on every workstation and server. It can push scripts. It can push software. That is the entire product. Whoever owns the console owns the fleet, and ransomware crews have been walking in through RMM platforms for years because it is the shortest path from one server to every endpoint at once.
You cannot patch this yourself. You can ask one question, today, in writing: which N-central build are we on, and when did you apply Hotfix 4? "We're aware of it" is not an answer. A build number is an answer.
While you have their attention, ask two more. Is the N-central console reachable from the public internet, or does it sit behind a VPN? And is MFA enforced on every technician account, including the service accounts nobody logs into? The vendor patch closes this CVE. Those two controls are what limit the blast radius of the next one.
Key takeaways
- CVE-2026-86218 is a CVSS 10.0 pre-authentication RCE in N-able N-central, published September 6, 2026
- Fixed in build 2026.3.1.14 (2026.3 Hotfix 4); all earlier releases including 2025.4, 2026.1, 2026.2 are affected
- N-able reports no confirmed exploitation yet — cloud-hosted instances are already patched, on-prem is the customer's job
- The CVSS vector scores high impact on downstream systems, not just the N-central server itself
- If a provider manages your machines, get the build number in writing and confirm the console is not internet-facing
You inherit every vendor your IT provider runs. We map the tools that hold privileged access to your systems, put the patch questions in the contract, and build automation you can actually audit. Book a stack audit or see how we work.
Sources: N-able status advisory, CVE-2026-86218 record, Rapid7 on CVE-2026-18577.
- #n-central
- #cve
- #msp
- #rmm
- #security
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
Starlette BadHost: one Host header bypasses your auth
CVE-2026-48710 lets a malformed Host header poison request.url.path and skip path-based middleware. CISA KEV, due September 16. Upgrade Starlette to 1.0.1.
Read itSwitchvox CVE-2026-9586: your phone system runs code
Unauthenticated SQL injection in Sangoma Switchvox's /pa endpoint gives RCE. Patched July 14, exploited August 30, ~4,000 boxes exposed. Upgrade to 8.4.0.2.
Read it