Powered by MOMENTUMMEDIA
For breaking news and daily updates, subscribe to our newsletter

Patch now! Hackers are targeting yet another N-able N-central vulnerability

CVE-2026-86218 is a perfect 10 vulnerability only disclosed this month, and exploitation is under way.

Wed, 09 Sep 2026
Patch now! Hackers are targeting yet another N-able N-central vulnerability

Security experts are warning that malicious actors are already taking advantage of yet another serious vulnerability in the N-able N-central remote management platform, the third such flaw reported in the last four weeks.

N-able disclosed CVE-2026-86218 earlier this month, telling its customers that they needed to “upgrade to N-central 2026.3 HF4 immediately to protect their environment”.

The vulnerability has a CVSS score of ten and could lead to remote code execution on an N-central server.

 
 

“This vulnerability was responsibly disclosed by a third party through our security disclosure program,” N-Able said in a September 6 advisory.

“At this time, we have no confirmations that this vulnerability has been exploited in production environments, but unpatched systems remain at risk.”

However, that potential risk has now evolved into a very real one, with CVE-2026-86218 added to the US Cybersecurity & Infrastructure Security Agency’s Known Exploited Vulnerabilities Catalog just two days later, on September 9.

Speaking to Cyber Daily, Yordan Ganchev, principal threat intelligence specialist at exposure management firm watchTowr, called the vulnerability the kind of “frown-inducing” bug that only comes along once in a while.

“At the tail end of last week, that included one exploited in the wild across all versions of N-able N-central, a product designed to ‘enable’ IT admins (and bad guys) to deploy software across an enterprise estate,” Ganchev said.

“The newly disclosed vulnerabilities in N-able include CVE-2026-86218, a pre-authentication vulnerability that enables remote code execution on vulnerable systems exposed across the internet. The combination of multiple hotfixes and reported exploitation strongly signals that this situation is serious.”

Ganchev said watchTowr had been able to reproduce the vulnerability to understand its impact, which could lead to changes made to N-central propagating across all connected systems.

“This is precisely why N-central is so strategically valuable to threat actors, especially ransomware gangs. The product is widely used by MSPs, MSSPs, and large IT organizations to manage entire customer and corporate environments,” Ganchev said.

“Compromise N-central, and you gain access to all connected computers and downstream systems. Based on historical events, AI-enabled attackers are unlikely to be far behind.”

According to Ganchev, N-central users need to prioritise patching – but even that may not be the entire solution.

“Organisations running internet-facing N-central instances should prioritize upgrading to a patched release. However, as is now quickly becoming the new normal, patching alone is not enough,” Ganchev said.

“Organisations must also review their environment for indicators of compromise and anomalous activity that suggest the vulnerability has already been exploited before patching. Ransomware threat actors have historically exploited this product in past campaigns, and this vulnerability is as severe as it gets.”

The latest safe version of N-central is 2026.3.1.14, which can be upgraded to directly from the following versions:

  • 2025.4
  • 2026.1
  • 2026.2
  • 2026.3
  • 2026.3.1 (Hotfix 1)
  • 2026.3.1 (Hotfix 2)

N-able recommends that customers using older versions of N-central upgrade to the versions above and then to the latest hotfix version as soon as possible.

Just last month, the Australian Signals Directorate’s Australian Cyber Security Centre issued a High Alert regarding exploitation of two earlier vulnerabilities in N-central, CVE-2026-18556 and CVE-2026-18577, both of which had a CVSS score of 8.2.

“ASD’s ACSC has observed the targeting of vulnerabilities affecting the N-able N-central product within Australia,” the ACSC said in a High Alert: Act Quickly email circulated late on 19 August.

It probably won’t be long until we see another ASD advisory.

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.
Tags: