N-able released its fourth hotfix in five weeks for its N-central remote monitoring and management platform, this time for a flaw that gives an unauthenticated attacker full "god-mode" access to the console. Tracked as CVE-2026-86218 and scored 10.0, the pre-authentication remote code execution zero-day is being exploited and supersedes all earlier hotfixes, so on-premises systems still on the third hotfix remain vulnerable and must apply the fourth. Hosted instances have already been patched. Researchers also disclosed a separate chain that lets attackers bypass access controls to create unauthorized administrator accounts. Because N-central manages many downstream endpoints, a compromise can cascade across every customer it serves.