N-able shipped its fourth emergency hotfix for N-central in five weeks on September 5, this time for CVE-2026-86218, a critical, pre-authenticated remote code execution flaw in the remote monitoring and management platform that thousands of managed service providers use to administer client networks.
N-able’s own status page describes the bug as allowing pre-authenticated RCE on the N-central server itself, disclosed through the company’s responsible-disclosure program. Its public advisory says there is no confirmation of exploitation in production. A separate, more urgent customer notice, reported by Help Net Security, called the same flaw a zero-day and said it “has been observed being exploited in the wild,” a direct contradiction of the public advisory’s language. Security firm Huntress independently flagged the bug alongside two other high-severity N-central issues N-able patched over the same weekend, saying it first learned of the flaw from a Discord post by an N-able employee, ahead of the company’s own hotfix announcement.
The pattern matters more than any single CVE. This is N-able’s third distinct N-central remote-access vulnerability disclosed since early August, following an earlier flaw whose first patch failed to hold. For a platform that exists specifically to give MSPs privileged remote access into hundreds of downstream customer networks, a fourth hotfix in five weeks is not just a patching cadence problem, it is a supply-chain concentration risk: every unpatched N-central server is a single point of failure for every network it manages.
Security teams running on-premises N-central should upgrade to build 2026.3.1.14 (Hotfix 4) immediately rather than waiting for a scheduled maintenance window, and should audit N-central user accounts for unexpected additions, per N-able’s own recommendation. Hosted N-central customers have already received the patch automatically. Given the discrepancy between N-able’s public “no confirmed exploitation” language and its own urgent customer notice describing active exploitation, MSPs should treat this as exploited until their own log review proves otherwise, not wait for public confirmation that may lag the private one by days, the same lesson this month’s other pre-authenticated root-access advisories have carried.
Source: N-able