Security bulletin with exclamation point symbol in the middle of the screen
Security bulletin with exclamation point symbol in the middle of the screen

CVE-2026-86218: Active Exploitation of N-able N-central: Critical Pre-Auth Remote Code Execution (RCE) Vulnerability

Security bulletin with exclamation point symbol in the middle of the screen
6 min read

Threat Summary

A maximum-severity (CVSS 10.0) vulnerability CVE-2026-86218 has been discovered in N-able N-central prior to build 2026.3.1.14. This flaw allows unauthenticated attackers to execute arbitrary code on the N-central server before authentication enabling remote takeover of the platform. The vulnerability is classified as static code injection (consistent with CWE-96) in a public-facing application endpoint.

CVE-2026-86218 may be exploited in conjunction with authentication bypass vulnerabilities CVE-2026-86206 and CVE-2026-86207, which allow adversaries to chain attacks, bypassing console authentication and creating attacker-controlled administrative accounts. The combination of these flaws enables full takeover of RMM infrastructure, thus amplifying the potential scope and impact of an incident.

CISA added CVE-2026-86218 to its Known Exploited Vulnerabilities (KEV) catalog on September 8th. The vulnerability was initially disclosed and patched via Hotfix 4 (2026.3.1.14) on September 6, 2026. Exploitation was observed prior to public disclosure, and independent researchers have reproduced the vulnerability. Unpatched systems are at extreme risk, and immediate action is necessary to remediate against this vulnerability.

Arctic Wolf has detections in place for N-able N-central to mitigate exposure. However, patching is most effective security measure against this threat.

Recommendations

  • Upgrade all N-central on-premises servers immediately to version 2026.3.1.14 (Hotfix 4) or later, available via the N-able Support portal.
    • This fully remediates CVE-2026-86218 and supersedes prior hotfixes (including Hotfix 3, which addressed CVE-2026-86206/86207).
  • Hosted (N-central Online, NCOD) environments have been patched by N-able.
  • Audit all N-central administrative accounts, and look for suspicious/unrecognized users (especially with emails ending in “.invalid”).
  • Rotate administrator/service credentials if compromise is suspected and review endpoint integrity especially for MSPs managing downstream clients.

Temporary Workarounds

If immediate patching is not possible, apply these temporary mitigations:

  • Firewall N-central web interface to permit only trusted IPs/VPN.
  • Segment your N-central server from other network segments and use just-in-time access for administration.
  • Enforce multi-factor authentication (MFA) for all administrative access, recognizing that this is a partial mitigation only for related vulnerabilities.

References:

Share this post: