N-able has pushed an urgent security update for its N-central RMM platform, addressing a maximum-severity remote code execution vulnerability tracked as CVE-2026-86218. The flaw allows unauthenticated attackers to execute arbitrary code on exposed N-central instances with low complexity. The company released N-central 2026.3 Hotfix 4 on Saturday and urged customers to apply it immediately.
Internet security nonprofit Shadowserver Foundation reports nearly 1,500 N-central servers remain exposed online, predominantly in the United States and Europe. While N-able stated it has "no confirmations that this vulnerability has been exploited in production environments," it acknowledged that unpatched systems are at risk.
However, cybersecurity firm Huntress has flagged CVE-2026-86218 as a potential zero-day, along with two other high-severity vulnerabilities (CVE-2026-86206 and CVE-2026-86207) that were also patched over the weekend. Those flaws could allow attackers to bypass authentication and gain full access to the platform. Huntress noted that in a previous incident observed in a customer environment, logs had already rotated, making it impossible to determine which of the three CVEs was exploited.
"On-premises N-central users must apply HF4 immediately, as systems running HF3 remain vulnerable to this newly disclosed flaw," Huntress warned. The company had previously patched the two other bugs in N-central 2026.3 Hotfix 3, also released over the weekend.
The discovery follows a pattern of attacks targeting MSPs, which serve as high-value targets because compromising a single N-central instance can give attackers access to multiple downstream client networks. N-able has not yet provided details on the technical nature of the exploit.