HackMyIP
← Back to News
2026-09-07 The Hacker News

N-able N-central Hotfix 4 Patches Critical 10.0 RCE Zero-Day

VulnerabilityZero-DayIncident Response

N-able has shipped its fourth hotfix in five weeks for the on-premises N-central remote monitoring and management (RMM) platform, addressing a maximum-severity vulnerability that enables unauthenticated remote code execution on the N-central server. Tracked as CVE-2026-86218 and assigned a CVSS 4.0 score of 10.0 by N-able acting as the CVE Numbering Authority, the flaw is classified as a static code injection weakness (CWE-96). It affects every N-central build prior to 2026.3.1.14, including servers already upgraded to Hotfix 3 (2026.3.1.13), which N-able had released roughly eight hours earlier for two unrelated flaws. Hosted N-central (NCOD) instances have been patched automatically, while on-premises administrators are urged to upgrade immediately. Direct upgrade paths are documented for 2025.4, 2026.1, 2026.2, 2026.3, and the 2026.3.1 hotfix series, and agents do not need to be upgraded to be protected against this CVE.

Notably, N-able's own communications offer conflicting accounts of exploitation status. The Hotfix 4 release notes and status post state that the vulnerability was responsibly disclosed through the company's disclosure program and that N-able has "no confirmations" of in-the-wild exploitation, even as the same documentation labels it a "critical zero-day vulnerability." The incident notice on N-able's uptime status page goes further, asserting that an independent researcher alerted the company to a flaw unrelated to prior CVEs and that the issue "has been observed being exploited in the wild." The notice provides no details on who observed exploitation, the location, the timeline, or any threat actor attribution, and as of September 7 the incident remained listed as open. Neither the release notes, status post, nor incident notice include indicators of compromise, interim mitigations, or detection guidance beyond auditing N-central user accounts for unexpected entries.

Huntress, which has been monitoring active attacks against N-central since August, is urging administrators to lock down exposure until patches land. Recommended actions include IP allowlisting or VPN-gated access to the N-central console, and where a server remains internet-reachable, taking it offline until 2026.3.1.14 is applied. Defenders should immediately audit their perimeter with a port scanner to confirm N-central consoles are not exposed on the public internet, and validate TLS posture on any remote management endpoints using an SSL/TLS checker. Because authentication-free RCE on an RMM platform is a high-value pivot point for downstream compromise, incident response teams should also review privileged accounts, audit agent communications, and hunt for unexpected user additions while the open status page reflects continued investigation.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

My IP →IP Lookup →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →