N-able is urging users of on-premises N-central to immediately apply its patch for an unauthenticated remote code execution (RCE) vuln to its N-central endpoint management platform, as it’s currently being actively exploited. The platform is widely used among managed service providers (MSPs and MSSPs), and many internal corporate enterprises are also users.
The vulnerability is tracked as CVE-2026-86218 with a CVSS score of 10/10, and was discovered after N-able patched two other flaws in N-central.
“This critical zero-day vulnerability, CVE-2026-86218, could allow pre-authenticated access to the N-central server if exploited. We communicated this 2026.3 hotfix earlier today, and we want to use this post as a reminder to upgrade immediately if you haven’t already, so we can help keep you and your customers protected,” the company’s alert reads. “Review your logs for scanning activity. We’ve observed scans originating from the IP range 23.234.64.0/18 attempting to exploit this vulnerability. Check your logs for any connections from this range.”
The alert also notes that N-central hosted environments don’t require the patch as it was deployed server-side.
You can read the alert here: N-central Security Update – Take Action to Apply 2026.3 HF4 – N-able
Waseem Ahmed, Head of Engineering at Secure.com
N-able makes N-central, software that IT teams and managed service providers use to watch over and control large numbers of customer computers from one central console. That reach is exactly why this bug is so dangerous.
A single flaw rated 10 out of 10 lets an attacker run code on the N-central server without any login or password first, so one weak spot can open the door to every client network hanging off that platform. Attackers love this kind of target because it turns one break-in into many.
On-premises teams should apply the 2026.3 HF4 hotfix right now, hunt their logs for scans from the flagged IP range, and look for strange new admin accounts. Trusted management tools deserve the same hard scrutiny you give the front door, because attackers already treat them as the shortest path in.
Suzu Labs CTO Denis Calderone:
The severity really comes down to the unprecedented amount of trust it has over its operating environment. It has so much control that you can basically think of a compromised N-central server as having control of a fleet of trojanized nodes; since you own the server, you automatically control all of its nodes. N-able is commonly deployed as an MSP tool, and oftentimes the end client isn’t even aware that they have N-able running because the MSP often white labels the tool as their own. What really worries me is the organization that doesn’t know they have N-able combined with the MSP that hasn’t patched yet. If you want an example of “history repeating” venture back to 2021 when Kaseya VSA got similarly popped; same results.
And the velocity here has our attention. This is N-central’s fourth emergency hotfix in five weeks and their fifth CVE since August. Huntress confirmed a compromised customer environment on September 4, two days before this patch even dropped. Someone is actively picking this platform apart, and the downstream businesses that are most exposed have no mechanism to even know whether their MSP has kept up with the patches.
If you use on-premises N-central, you need to patch all the things ASAP as it is a safe bet that the bad guys are going to leverage this against you if your on-premises N-central instance is attacked.
Related
This entry was posted on September 8, 2026 at 6:06 pm and is filed under Commentary with tags Hacked. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
N-able warns MSSPs, MSPs & orgs: patch critical N-central vulnerability NOW
N-able is urging users of on-premises N-central to immediately apply its patch for an unauthenticated remote code execution (RCE) vuln to its N-central endpoint management platform, as it’s currently being actively exploited. The platform is widely used among managed service providers (MSPs and MSSPs), and many internal corporate enterprises are also users.
The vulnerability is tracked as CVE-2026-86218 with a CVSS score of 10/10, and was discovered after N-able patched two other flaws in N-central.
“This critical zero-day vulnerability, CVE-2026-86218, could allow pre-authenticated access to the N-central server if exploited. We communicated this 2026.3 hotfix earlier today, and we want to use this post as a reminder to upgrade immediately if you haven’t already, so we can help keep you and your customers protected,” the company’s alert reads. “Review your logs for scanning activity. We’ve observed scans originating from the IP range 23.234.64.0/18 attempting to exploit this vulnerability. Check your logs for any connections from this range.”
The alert also notes that N-central hosted environments don’t require the patch as it was deployed server-side.
You can read the alert here: N-central Security Update – Take Action to Apply 2026.3 HF4 – N-able
Waseem Ahmed, Head of Engineering at Secure.com
N-able makes N-central, software that IT teams and managed service providers use to watch over and control large numbers of customer computers from one central console. That reach is exactly why this bug is so dangerous.
A single flaw rated 10 out of 10 lets an attacker run code on the N-central server without any login or password first, so one weak spot can open the door to every client network hanging off that platform. Attackers love this kind of target because it turns one break-in into many.
On-premises teams should apply the 2026.3 HF4 hotfix right now, hunt their logs for scans from the flagged IP range, and look for strange new admin accounts. Trusted management tools deserve the same hard scrutiny you give the front door, because attackers already treat them as the shortest path in.
Suzu Labs CTO Denis Calderone:
The severity really comes down to the unprecedented amount of trust it has over its operating environment. It has so much control that you can basically think of a compromised N-central server as having control of a fleet of trojanized nodes; since you own the server, you automatically control all of its nodes. N-able is commonly deployed as an MSP tool, and oftentimes the end client isn’t even aware that they have N-able running because the MSP often white labels the tool as their own. What really worries me is the organization that doesn’t know they have N-able combined with the MSP that hasn’t patched yet. If you want an example of “history repeating” venture back to 2021 when Kaseya VSA got similarly popped; same results.
And the velocity here has our attention. This is N-central’s fourth emergency hotfix in five weeks and their fifth CVE since August. Huntress confirmed a compromised customer environment on September 4, two days before this patch even dropped. Someone is actively picking this platform apart, and the downstream businesses that are most exposed have no mechanism to even know whether their MSP has kept up with the patches.
If you use on-premises N-central, you need to patch all the things ASAP as it is a safe bet that the bad guys are going to leverage this against you if your on-premises N-central instance is attacked.
Share this:
Like this:
Related
This entry was posted on September 8, 2026 at 6:06 pm and is filed under Commentary with tags Hacked. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.