← All articles

N-able ships fourth N-central hotfix in five weeks for exploited pre-auth flaw

N-able released its fourth hotfix in five weeks for its N-central remote monitoring and management platform, this time for a flaw that gives an unauthenticated attacker full "god-mode" access to the console. Tracked as CVE-2026-86218 and scored 10.0, the pre-authentication remote code execution zero-day is being exploited and supersedes all earlier hotfixes, so on-premises systems still on the third hotfix remain vulnerable and must apply the fourth. Hosted instances have already been patched. Researchers also disclosed a separate chain that lets attackers bypass access controls to create unauthorized administrator accounts. Because N-central manages many downstream endpoints, a compromise can cascade across every customer it serves.

Check
Apply N-central hotfix 4 immediately on any on-premises server, since prior hotfixes do not cover this flaw, then audit the console's user list for unauthorized administrator accounts.
Affected
Organizations and managed-service providers running on-premises N-able N-central (CVE-2026-86218); an unauthenticated attacker can execute code and gain full control of the console, and from there potentially reach every managed endpoint.
Fix
Patch to the latest hotfix, strictly limit inbound access to the N-central console, audit for rogue admin accounts and recent changes, monitor managed endpoints, and treat any exposed unpatched server as compromised.