AI Weekly Malaysia

Back to items Summaries

N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw

ID
22069
Status
summarized
Published
07 Sep 2026, 4:31 PM
Fetched
07 Sep 2026, 6:38 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/n-able-issues-fourth-n-central-hotfix.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
2.5
Created
07 Sep 2026, 6:39 PM
Tags
Audience
developers

What happened

N-able released its fourth hotfix in five weeks for N-central, an on-premises RMM platform, patching CVE-2026-86218 — a CVSS 10.0 unauthenticated remote code execution flaw (CWE-96 static code injection) affecting every build before 2026.3.1.14. N-able's own communications conflict on whether the flaw has been exploited in the wild, with incident notices suggesting exploitation and release notes saying it is unconfirmed; no IOCs or mitigations were provided beyond auditing for unexpected users.

Why it matters

If you or your MSP runs on-premises N-central, upgrade to 2026.3.1.14 immediately and restrict console access via IP allowlisting or VPN — Huntress reports active attacks since August. For everyone else, this is not actionable; it is a niche RMM platform, not a tool this audience typically ships with.

Discussion angle

The vendor's own channels disagreeing on whether exploitation occurred — and shipping four hotfixes in five weeks with no IOCs — is a case study in how not to communicate during an active security incident.

Top