Skip to content
feed: live
>_0dayNews
supply chain
● Breaking

N-central Under Active Attack: Patch CVE-2026-86218 Now

BleepingComputer reports N-central servers under active attack one day after N-able's CVSS 10.0 pre-auth RCE disclosure. Update to version 2026.3.1.14 immediately.

N-central Under Active Attack: Patch CVE-2026-86218 Now
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
loopNadia "Loop" Park·Published ·1 min read

BleepingComputer reported on September 7 that N-central servers are under active attack. The target is CVE-2026-86218, the CVSS 4.0: 10.0 pre-authentication remote code execution N-able disclosed a day earlier. Our September 6 writeup has the full technical detail: CWE-96 static code injection, no credentials required, no user interaction, fully network-accessible. The time between disclosure and confirmed exploitation: one day.

N-central is the operational layer of MSP infrastructure. Agent deployment, patch scheduling, remote script execution across every managed client endpoint runs through it. A compromised N-central instance gives an attacker the same administrative reach across every client simultaneously. Ransomware operators have targeted RMM platforms for exactly that reason, and N-able has seen this before: CVE-2026-18577, an authentication bypass in an earlier N-central version, was added to the CISA Known Exploited Vulnerabilities catalog in August following confirmed exploitation. That is two critical pre-authentication vulnerabilities in eight weeks.

No workarounds exist. The N-able advisory documents no mitigations short of isolation from external network access. The pattern holds for management-layer tools: JFrog Artifactory’s CVE-2026-82329 moved from disclosure to confirmed active exploitation in days earlier this month.

Patch to version 2026.3.1.14. Check the installed version at System > Updates.

Related CVEs
  • [ CRITICAL ]CVE-2026-86218N-central Pre-Authentication Remote Code Execution

Found this useful? Share it.