Cyber Security News

CISA Warns of N-able N-central RCE Vulnerability Exploited in the Wild

The Cybersecurity and Infrastructure Security Agency has added a maximum-severity flaw in N-able’s N-central remote monitoring and management platform to its Known Exploited Vulnerabilities catalog, confirming that attackers are actively abusing the bug against real-world targets.

The vulnerability, tracked as CVE-2026-86218, carries a perfect CVSS score of 10.0 and allows unauthenticated remote code execution, making it one of the most dangerous flaws to hit the managed service provider ecosystem this year.

CISA classifies CVE-2026-86218 as a static code injection vulnerability tied to CWE-96, meaning attackers can inject malicious directives into statically saved, executable code on the N-central server.

N-able N-central RCE Vulnerability

Because the flaw requires no authentication or user interaction, any threat actor with network access to an exposed N-central instance could run arbitrary commands, giving them a foothold not just into the platform itself but into every downstream endpoint an MSP manages through it.

The bug was reported to N-able through the company’s responsible disclosure program and affects all on-premises N-central builds prior to version 2026.3.1.14, spanning the 2025.4, 2026.1, 2026.2, and 2026.3 release lines, including systems that had already applied earlier hotfixes in the same release cycle.

N-able shipped Hotfix 4 for N-central 2026.3 on September 5-6, 2026, bringing on-premises deployments to build 2026.3.1.14. This marked the fourth emergency hotfix the company issued within five weeks, following earlier fixes for separate authentication bypass and RCE issues tracked as CVE-2026-86206 and CVE-2026-86207.

Hosted N-central customers did not need to take action since N-able patched those environments server-side, but on-premises administrators were urged to upgrade immediately.

While N-able initially stated it had no confirmation of exploitation in production environments, CISA’s KEV listing and independent research from Huntress indicate otherwise, with at least one customer’s N-central instance reportedly compromised on September 4, two days before the patch shipped. CISA added the flaw to its catalog on September 8, 2026.

Under Binding Operational Directive 26-04, federal civilian agencies running affected N-central instances have until September 11, 2026, to apply mitigations, and CISA is requiring forensic triage on any system found exposed prior to patching. The directive also instructs agencies to follow BOD 26-04 guidance for cloud services or discontinue use of the product entirely if mitigations cannot be applied in time.

Given N-central’s widespread use among MSPs managing thousands of downstream client networks, security teams should treat this as an urgent, organization-wide priority rather than a routine patch cycle.

Administrators should upgrade on-premises instances to 2026.3.1.14 immediately, audit internet exposure of their N-central servers, and review logs for signs of compromise dating back to early September, since a compromised RMM server can serve as a single point of entry into an entire client base.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

4 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

13 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

14 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

15 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

15 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

15 hours ago