Skip to content
feed: live
>_0dayNews
supply chain

N-able Patches CVSS 10 Pre-Auth RCE in N-central

N-able's N-central RMM platform has a pre-authentication remote code execution flaw, CVSS 4.0: 10.0, affecting all versions before 2026.3.1.14. Patch immediately.

N-able Patches CVSS 10 Pre-Auth RCE in N-central
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
loopNadia "Loop" Park·Published ·1 min read

N-central is the management layer for MSP operations: agent deployment, patch scheduling, remote monitoring, and script execution across thousands of client endpoints from a single console. A compromised N-central server gives an attacker that same reach, across every managed client at once.

N-able disclosed CVE-2026-86218 on September 6, 2026. The flaw is a pre-authentication remote code execution, scored at CVSS 4.0: 10.0. It is network-accessible and requires no credentials. An unauthenticated attacker with a network path to an affected server can execute code on the host without logging in.

The underlying classification is CWE-96, a static code injection category where user-controlled input reaches an execution context without adequate sanitization. Because the vulnerable path requires no authentication, the exposed listener is the full attack surface.

All N-central versions before 2026.3.1.14 are affected. N-able has released 2026.3.1.14 as the fix. The advisory documents no workarounds.

This is the second critical flaw in N-central in under two months. CISA added CVE-2026-18577, an authentication bypass in an earlier build, to the Known Exploited Vulnerabilities catalog in August. Active exploitation of that flaw was confirmed before CISA’s listing. RMM platforms are a well-documented attack vector for ransomware operators: a single compromise of the management layer translates to payload delivery across the entire managed fleet. The CISA KEV catalog’s September addition of seven actively exploited flaws included similar supply-chain access vectors, as did JFrog Artifactory’s exploited authentication bypass.

CVE-2026-86218 has no confirmed exploitation at the time of disclosure. That window between a CVSS 10.0 pre-auth RCE disclosure and active exploitation has historically been short for RMM and build-infrastructure tools.

Update N-central to 2026.3.1.14. Instances that cannot receive the update immediately should be isolated from external network access until patching is complete.

Related CVEs
  • [ CRITICAL ]CVE-2026-86218N-central Pre-Authentication Remote Code Execution

Found this useful? Share it.