N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw
N-able has released its fourth hotfix for N-central, addressing a critical zero-day vulnerability (CVE-2026-86218) that allows unauthenticated remote code execution. While N-able initially stated the vulnerability was not exploited, independent research by Huntress indicates it *has* been exploited in the wild, with a proof-of-concept exploit chain successfully reproduced. This is the second summer in a row N-central has been targeted with in-the-wild attacks, highlighting a persistent security issue.
N-able has released its fourth hotfix in five weeks for N-central, a remote monitoring and management platform, to address a critical zero-day vulnerability (CVE-2026-86218). This vulnerability allows unauthenticated remote code execution on N-central servers. The company initially stated that a third-party security researcher disclosed the vulnerability, and that N-able had no confirmation of exploitation in production environments. However, Huntress, a cybersecurity firm, has independently confirmed that the vulnerability has been exploited in the wild, successfully reproducing a proof-of-concept exploit chain against build 2026.3.1.10. This exploit chain utilized one or both of the two flaws addressed in Hotfix 3.
This is the second summer in a row N-central has been targeted with in-the-wild attacks. In August 2025, two other flaws in the product, CVE-2025-8875 and CVE-2025-8876, were added to the U.S. Cybersecurity and Infrastructure Security Agency (CISA) ‘Known Exploited Vulnerabilities’ catalog on the same day N-able released fixes for them. The initial Hotfix 3 vulnerabilities – CVE-2026-86206 and CVE-2026-86207 – allowed unauthorized access to internal APIs and an authentication bypass, respectively, and were also added to CISA’s catalog. N-able’s initial fix for these vulnerabilities was deemed incomplete.
Previously, an intrusion detected on July 31 saw attackers leveraging an authentication bypass to gain administrative access to N-central servers. They then utilized the platform’s ‘Take Control’ feature to reach managed endpoints and register Cloudflare tunnel services on those devices, maintaining access even after the route through N-central was severed. The company initially stated a limited number of customers were affected. The vulnerability is classified as a ‘critical zero-day’ by N-able, though they do not define the term. The Hacker News has reached out to N-able for clarification on the current status of exploitation confirmation.
