CISA Warns of Critical N-able N-central RCE Vulnerability Exploited in Attacks
Key Takeaways The Cybersecurity and Infrastructure Security Agency (CISA) has flagged a critical remote code execution (RCE) vulnerability in N-able N-central, confirming active exploitation. Tracked...
Key Takeaways
- The Cybersecurity and Infrastructure Security Agency (CISA) has flagged a critical remote code execution (RCE) vulnerability in N-able N-central, confirming active exploitation.
- Tracked as CVE-2026-86218, the flaw has a CVSS score of 10.0, allowing unauthenticated attackers to execute arbitrary code.
- All on-premises N-central versions prior to 2026.3.1.14 are affected, including those with previous hotfixes.
- N-able has released a patch (Hotfix 4 for 2026.3), bringing on-premises deployments to build 2026.3.1.14.
- Given the widespread use of N-central by Managed Service Providers (MSPs), immediate patching and compromise detection are critical.
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a severe warning regarding a critical vulnerability in N-able’s N-central remote monitoring and management (RMM) platform. The flaw, now added to CISA’s Known Exploited Vulnerabilities (KEV) catalog, is actively being leveraged by threat actors against real-world targets.
Table Of Content
Critical N-able N-central RCE Vulnerability Under Attack
Designated as CVE-2026-86218, this vulnerability commands a maximum CVSS score of 10.0, indicating its extreme severity. It enables unauthenticated remote code execution, positioning it as one of the most perilous security risks to impact the managed service provider (MSP) ecosystem this year.
CISA has categorized CVE-2026-86218 as a static code injection vulnerability, aligning with CWE-96. This classification means attackers can inject malicious directives into statically saved, executable code residing on the N-central server, effectively taking control.
The absence of authentication or user interaction requirements makes this flaw particularly dangerous. Any threat actor with network access to an exposed N-central instance can execute arbitrary commands. This grants them a significant foothold not only within the RMM platform itself but also across every downstream endpoint an MSP manages through it.
The vulnerability was initially reported to N-able through its responsible disclosure program. It impacts all on-premises N-central builds preceding version 2026.3.1.14. This includes the 2025.4, 2026.1, 2026.2, and 2026.3 release lines, even if earlier hotfixes within the same release cycle had been applied.
N-able released Hotfix 4 for N-central 2026.3 between September 5 and 6, 2026, updating on-premises deployments to build 2026.3.1.14. This marked the fourth emergency hotfix from the company within a five-week period, following previous fixes for distinct authentication bypass and RCE issues identified as CVE-2026-86206 and CVE-2026-86207. Hosted N-central customers were automatically patched by N-able and did not need to take manual steps, but on-premises administrators were strongly advised to upgrade without delay.
While N-able initially reported no confirmed exploitation in production environments, CISA’s KEV listing and independent research from Huntress contradict this, indicating at least one customer’s N-central instance was compromised as early as September 4, two days before the patch became available. CISA formally added the vulnerability to its catalog on September 8, 2026.
Under Binding Operational Directive 22-01, federal civilian agencies operating affected N-central instances must apply mitigations by September 11, 2026. CISA further mandates forensic triage on any system found to have been exposed prior to patching. The directive also instructs agencies to adhere to BOD 22-01 guidance for cloud services or cease using the product entirely if timely mitigations are not feasible.
Considering N-central’s extensive deployment among MSPs, which manage thousands of client networks, security teams must treat this vulnerability as an urgent, organization-wide priority rather than a routine patching exercise.
What You Should Do
- Immediately upgrade all on-premises N-central instances to version 2026.3.1.14.
- Conduct a thorough audit of your N-central servers’ internet exposure. Restrict network access to the N-central instance to only necessary IP ranges.
- Review logs for any indicators of compromise, particularly for activity dating back to early September. A compromised RMM server can serve as a single point of entry into an entire client base.
- Implement strong network segmentation to isolate your N-central server from other critical infrastructure.
- Ensure robust endpoint detection and response (EDR) solutions are active and monitored on all managed endpoints.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.