Skip to content
Threat Feed
critical threat exploited

Critical RCE Vulnerability in N-able N-central

A critical unauthenticated remote code execution vulnerability (CVE-2026-86218) in N-able N-central is under active exploitation, allowing attackers to gain full system control.

CVE search metadata

CVE search record: CVE-2026-86218. EPSS: 0.41%. KEV: no. Product: N-central (< 2026.3.1.14), N-Central (< 2026.3.1.14). Brief: Critical RCE Vulnerability in N-able N-central. Brief link: https://feed.craftedsignal.io/briefs/2026-09-n-central-rce/

What's new

  • 1. new product Sep 7, 13:33 via bsi

N-able has identified a critical vulnerability, CVE-2026-86218, affecting its N-central remote monitoring and management platform. This vulnerability carries a CVSS score of 10 and permits unauthenticated, remote attackers to execute arbitrary code on the underlying system. The flaw is currently being exploited in the wild, posing an immediate risk to IT service providers and organizations managing IT systems via this software. N-central is frequently used by IT service providers, making it a high-value target for attackers aiming to pivot into the downstream environments of managed clients. All on-premises instances prior to version 2026.3.1.14 are susceptible to compromise, which results in full system take-over. Hosted N-able N-central (NCOD) instances have been patched by the vendor.

Impact

Successful exploitation of CVE-2026-86218 results in total system compromise. Given N-central's role as a central management platform, the impact includes potential massive data exfiltration, service disruption, and the ability for attackers to distribute secondary malware or ransomware across the entire managed infrastructure of the victim organization and their clients. The vulnerability is currently being actively exploited, necessitating immediate remediation for all on-premises deployments.

Recommendation

  • Prioritize the immediate upgrade of all on-premises N-central instances to version 2026.3.1.14 or later to mitigate CVE-2026-86218.
  • Monitor web server and application access logs for anomalous, unauthenticated POST requests or unusual execution patterns targeting N-central management ports.
  • Verify with N-able support or your IT service provider if you are currently running an on-premises version of the software.
  • Deploy endpoint detection and response (EDR) solutions on the servers hosting N-central to detect unauthorized process creation or command execution originating from the web application process.

Immediate actions

Upgrade on-premises N-central to 2026.3.1.14 or later

IT Operations 24h

Mitigations

Patch N-central to 2026.3.1.14

immediate IT Operations

CVE-2026-86218