N-able Patches Critical Zero-Day in N-central
N-able has released a critical hotfix to address a zero-day vulnerability (CVE-2026-86218) in its N-central endpoint management platform. The vulnerability allows unauthenticated remote code execution, and while server-side patches are in place, on-premises users need to apply the hotfix immediately to prevent potential exploitation. Initial attacks targeted the N-central API and appliance logs, and Huntress observed a campaign attempting to bypass authentication.
N-able has released a critical hotfix to address a zero-day vulnerability (CVE-2026-86218) in its N-central endpoint management platform. The vulnerability allows unauthenticated remote code execution, and while server-side patches are in place, on-premises users need to apply the hotfix immediately to prevent potential exploitation. Initial attacks targeted the N-central API and appliance logs, and Huntress observed a campaign attempting to bypass authentication.
Tracked as CVE-2026-86218, the security defect was discovered after N-able patched two other flaws in N-central, namely CVE-2026-86206 and CVE-2026-86207.
“This critical zero-day vulnerability, CVE-2026-86218, could allow pre-authenticated access to the N-central server if exploited,” N-able warns.
Administrators are also advised to check their deployments for newly created user accounts they don’t recognize. “At this time, we have no confirmations that this vulnerability has been exploited in production environments, but unpatched systems remain at risk,” N-able says.
The hotfix for the exploited zero-day supersedes the previously released patches for CVE-2026-86206 and CVE-2026-86207, two bugs that Huntress flagged as potentially chained together in the wild to bypass authentication and compromise N-central production environments.
“However, due to limited historical logging available directly on the appliance, we cannot definitively confirm which specific exploit the threat actor used to achieve their compromise, nor can we rule out the use of alternative vulnerabilities,” Huntress said on Saturday.
The cybersecurity firm observed attacks targeting N-central’s underlying API and appliance logs starting on September 4, 2026.