N-able Patches CVSS 10 Pre-Auth RCE in N-central
N-able's N-central RMM platform has a pre-authentication remote code execution flaw, CVSS 4.0: 10.0, affecting all versions before 2026.3.1.14. Patch immediately.

N-central is the management layer for MSP operations: agent deployment, patch scheduling, remote monitoring, and script execution across thousands of client endpoints from a single console. A compromised N-central server gives an attacker that same reach, across every managed client at once.
N-able disclosed CVE-2026-86218 on September 6, 2026. The flaw is a pre-authentication remote code execution, scored at CVSS 4.0: 10.0. It is network-accessible and requires no credentials. An unauthenticated attacker with a network path to an affected server can execute code on the host without logging in.
The underlying classification is CWE-96, a static code injection category where user-controlled input reaches an execution context without adequate sanitization. Because the vulnerable path requires no authentication, the exposed listener is the full attack surface.
All N-central versions before 2026.3.1.14 are affected. N-able has released 2026.3.1.14 as the fix. The advisory documents no workarounds.
This is the second critical flaw in N-central in under two months. CISA added CVE-2026-18577, an authentication bypass in an earlier build, to the Known Exploited Vulnerabilities catalog in August. Active exploitation of that flaw was confirmed before CISA’s listing. RMM platforms are a well-documented attack vector for ransomware operators: a single compromise of the management layer translates to payload delivery across the entire managed fleet. The CISA KEV catalog’s September addition of seven actively exploited flaws included similar supply-chain access vectors, as did JFrog Artifactory’s exploited authentication bypass.
CVE-2026-86218 has no confirmed exploitation at the time of disclosure. That window between a CVSS 10.0 pre-auth RCE disclosure and active exploitation has historically been short for RMM and build-infrastructure tools.
Update N-central to 2026.3.1.14. Instances that cannot receive the update immediately should be isolated from external network access until patching is complete.
- [ CRITICAL ]CVE-2026-86218N-central Pre-Authentication Remote Code Execution
Found this useful? Share it.


