N-able N-central Pre-Auth RCE Flaw Exploited in the Wild
- ID
- 22631
- Status
- summarized
- Published
- 09 Sep 2026, 12:27 PM
- Fetched
- 09 Sep 2026, 1:21 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/n-able-n-central-pre-auth-rce-flaw.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 3.5
- Created
- 09 Sep 2026, 1:25 PM
- Tags
- Audience
- developerssaas_founders
What happened
CISA added CVE-2026-86218 (CVSS 10.0), a pre-auth static code injection RCE in N-able N-central, to its Known Exploited Vulnerabilities catalog after active exploitation was confirmed. The flaw was patched in N-central 2026.3 Hotfix 4 (released September 5, 2026), while two related auth-bypass vulnerabilities (CVE-2026-86206 and CVE-2026-86207) were fixed the same day in Hotfix 3. Huntress reported a compromised fully-patched N-central production environment on September 4 but could not confirm which specific CVE was used due to limited appliance logging.
Why it matters
If your IT provider or MSP uses N-able N-central to manage your infrastructure, confirm they have applied Hotfix 4 immediately — this is a pre-auth RCE being actively exploited, meaning an unauthenticated attacker can take full control of the management server. Most builders won't run N-central directly, so this is only actionable if you can verify your vendor stack includes it.
Discussion angle
How many of us actually know which RMM or endpoint management tools our cloud providers or MSPs run — and whether a CVSS 10.0 in one of them is our problem or theirs?