What happened

CISA's September 8 alert listed CVE-2026-86218 as an "N-able N-central Static Code Injection Vulnerability," alongside the Adobe Commerce StyleSmuggler flaw (see our StyleSmuggler post) and two Windows bugs. The CVE record says only that "N-central is vulnerable to a pre-auth remote code execution" affecting releases before 2026.3.1.14.

This is the latest step in a run of N-central problems that Huntress has documented since August:

  • August 1 and 2: N-able disclosed CVE-2026-18556 and CVE-2026-18577 and shipped hotfix build 2026.3.1.7, followed by 2026.3.1.10 on August 6. Huntress saw attackers abuse N-central's Take Control remote access feature to move to domain controllers. By August 3, Huntress reported, 28.6% of reachable self-hosted N-central servers were still unpatched.
  • September 4: Huntress found that a fully patched N-central production environment had been compromised, with authentication bypassed and administrator accounts manipulated.
  • September 5: CVE-2026-86206 and CVE-2026-86207, two authentication bypass flaws that let an attacker create an administrator account, were fixed in Hotfix 3 (build 2026.3.1.13). Help Net Security credits Stephen Fewer of Rapid7 with finding them.
  • September 5 or 6: N-able released 2026.3 Hotfix 4 (build 2026.3.1.14) for CVE-2026-86218. The Hacker News and Help Net Security give September 5; Huntress gives September 6.

N-able's messaging on exploitation shifted. Help Net Security reports that the first advisory said there were "no confirmations that this vulnerability has been exploited in production," while a later customer notice said it "has been observed being exploited in the wild." watchTowr says it reproduced the exploit end to end and that it lets an attacker "make changes in N-central that can propagate across all connected systems." Huntress lists attacker IP addresses (largely commercial VPN exit nodes), probing of /remoteControlAction.do?method=getPierDetails, and new accounts whose email addresses end in .invalid.

Whether hosted N-central was ever exposed to this specific flaw is not fully clear from public sources: Help Net Security says both hosted and on-premises deployments were affected, and Huntress says hosted instances have already been patched by N-able. Either way, the action item sits with on-premises operators.

Why it matters if you run public infrastructure

An RMM console is a single point that can run code on every managed endpoint. For an MSP, that means every customer. watchTowr put it bluntly: "Compromise N-central, and you gain access to all connected computers and downstream systems." The console also has to be reachable by agents in the field, which is why many N-central servers answer on the public internet. And because Hotfix 3 was not enough, anyone who patched on September 5 and moved on is still exposed.

What to check this week

  1. Confirm the build is 2026.3.1.14 or later. Hotfix 3 (2026.3.1.13) does not fix this CVE. If you run anything older, install Hotfix 4 now.
  2. Restrict who can reach the console. Huntress advises restricting all inbound access to the N-central console and avoiding public exposure. If agents need to reach it from the internet, limit the admin login pages to known networks, and consider taking the server offline until the hotfix is on, as Huntress suggests for high-risk environments.
  3. Audit accounts. Look for administrator accounts you did not create, especially ones with email addresses ending in .invalid, and for recent changes to existing admin accounts.
  4. Review remote sessions and scripts. Check Take Control sessions, scheduled tasks and scripts pushed to endpoints since August, and look for Cloudflare tunnels or remote access tools you did not deploy.
  5. Tell your customers. If you are an MSP and your console was exposed and unpatched, your customers' incident response may need to start too.

How Attack Surface Scan covers this

Partially. N-central is not in the product catalog our vulnerability matching recognizes, so we will not raise a CVE finding for CVE-2026-86218 or tell you which build is running. What we do show is where your consoles are: every host under your verified domains, including ones found in certificate transparency logs, that answers on 443 or another web port we check (see Exposed services), the certificate it presents, and an alert when a new login page or listener appears. For an MSP that is the list of consoles to patch and restrict; the build number has to be checked in N-central itself. We never test the exploit. See Vulnerability matching for the products we do match.

Sources