N-able has now shipped four emergency hotfixes for its N-central remote monitoring and management platform in five weeks, and the latest one addresses a flaw that hit the maximum possible severity score. CVE-2026-86218, disclosed September 6, 2026, is a pre-authentication remote code execution bug carrying a CVSS score of 10.0, the ceiling of the scale. Security firm Huntress says the flaw has already been observed being exploited in the wild, even as N-able’s own release notes stopped short of confirming that. For the thousands of managed service providers who run N-central to watch over client networks, the past five weeks have turned a routine patch cycle into a running incident.
What Happened: A Fourth Emergency Patch in Five Weeks
N-able released N-central 2026.3 Hotfix 4, build 2026.3.1.14, on September 6, 2026, to close CVE-2026-86218. According to Huntress’s incident write-up, the company was alerted to the new CVE through a post from N-able’s own Jason Murphy in an MSPGeek Discord thread, hours before N-able published formal release notes. Murphy wrote that a third, independent researcher had flagged a new vulnerability that has been exploited in the wild that is unrelated to the previously disclosed CVEs, and later added in follow-up conversation that this one is a zero day.
That single sentence captures how strange this month has been for N-able. The fourth hotfix supersedes a third hotfix that shipped just one day earlier, on September 5, which itself patched two separate CVEs (CVE-2026-86206 and CVE-2026-86207) unrelated to a pair of vulnerabilities from early August. Four hotfixes, three CVE clusters, one vendor, five weeks. On-premises N-central customers who dutifully applied Hotfix 3 on September 5 woke up September 6 to discover their systems were still exposed to a maximum-severity bug. Hosted N-central (NCOD) customers, N-able says, were already patched by the time the advisory went out.
Inside CVE-2026-86218: What Makes It a 10.0
N-central is the RMM console MSPs use to remotely monitor, patch, and control every endpoint they manage for a client, meaning a single compromised N-central server can become a launchpad into dozens or hundreds of downstream networks at once. CVE-2026-86218 is classified under CWE-96, static code injection, and requires no authentication and no user interaction to trigger. Vulnerability tracker Rapid7’s database entry lists a base score of 10 (critical), and the flaw affects every N-central build prior to 2026.3.1.14, including servers already updated to Hotfix 3.
Threat intelligence firm IONIX’s threat center entry describes the bug in equally blunt terms: a pre-authentication remote code execution vulnerability in a widely deployed RMM product. Because N-central runs on a customized AlmaLinux 9 distribution and typically operates as a sealed appliance, Huntress notes it often ships without endpoint detection software installed on the appliance itself, which narrows the window in which defenders would normally catch an intrusion before it spreads.
The Vendor Said “No Confirmations.” Researchers Disagreed
N-able’s official Hotfix 4 release notes state plainly: “At this time, we have no confirmations that this vulnerability has been exploited in production environments, but unpatched systems remain at risk.” That line sits awkwardly next to what Huntress found elsewhere. Both the MSPGeek Discord post from N-able’s own Jason Murphy and N-able’s separate Active Incident page reportedly described the vulnerability as having been observed being exploited in the wild, a direct contradiction of the more cautious language in the formal release notes.
Huntress hedges its own findings, too. The firm says it cannot rule out whether CVE-2026-86206 and CVE-2026-86207, the pair patched a day earlier in Hotfix 3, were actually the vulnerabilities exploited in a compromised customer environment it investigated starting September 4, because logs on that server had already rotated by the time investigators looked. In plain terms: a fully patched N-central production server, running the version current at the time, got compromised anyway, and nobody can say with certainty which of three near-simultaneous bugs the attacker actually used.
Five Weeks, Three Vulnerability Clusters: The Full Timeline
Strip away the back-and-forth and the underlying sequence is straightforward to follow. It started in early August with a flaw that gave attackers what Huntress bluntly called “god-mode” access to the RMM console, no login required, across both hosted and self-hosted deployments. N-able’s response accelerated as each new discovery layered on top of the last.
| Date (2026) | Hotfix / Build | CVE(s) Addressed | What It Fixed |
|---|---|---|---|
| Aug 2 | Hotfix 1 (2026.3.1.7) | CVE-2026-18556, CVE-2026-18577 | Unauthenticated “god-mode” access to the N-central console |
| Aug 6 | Hotfix 2 (2026.3.1.10) | Same as above (hardening) | Additional hardening measures; required even for those who applied Hotfix 1 |
| Sept 5 | Hotfix 3 (2026.3.1.13) | CVE-2026-86206, CVE-2026-86207 | Authentication bypass chain allowing creation of unauthorized admin accounts |
| Sept 6 | Hotfix 4 (2026.3.1.14) | CVE-2026-86218 | Pre-auth remote code execution, CVSS 10.0, supersedes Hotfix 3 |
Huntress dates the discovery of the September cluster to September 4, when a customer’s fully patched N-central production environment was compromised. Investigators reproduced a working proof-of-concept exploit chain against the then-current build, shared it with N-able’s security team, and watched the vendor turn around a new hotfix within roughly 24 hours. Less than 24 hours after that, a third independent researcher surfaced the CVE-2026-86218 zero-day, forcing yet another emergency release.
How Attackers Are Actually Using the Access
Huntress’s telemetry shows a consistent pattern across the August intrusions it tracked. Attackers connected through N-central’s built-in Take Control feature using “MSP Support,” the tool’s default session username, then ran high-level reconnaissance aimed at identifying domain controllers before pulling a process list and moving laterally across multiple hosts. In one documented case, threat actors tore through downstream systems in an affected organization within a short window after the initial compromise, exactly the blast-radius risk that makes a centrally managed RMM tool so attractive to attackers in the first place.
The September activity looks different. Instead of abusing Take Control, Huntress says attackers are targeting the underlying API directly, probing an endpoint (/remoteControlAction.do?method=getPierDetails) to map appliance IDs before exploitation, then creating rogue accounts with subtly malformed email addresses, appending strings like “.invalid” to known N-able domains to slip past casual review. Huntress also worked directly with Cloudflare to take down tunnel infrastructure it believes attackers were using to maintain backdoor access into compromised consoles.
Detection guidance from Huntress's incident tracking (Sept. 2026 activity):
- Review: envoy_proxy_HTTPS.log and syslog ncentraldms on N-central appliances
- Flag: URL-encoded endpoint anomalies in API requests (e.g. %2F patterns)
- Audit: newly created user accounts for ".invalid" or spoofed-domain email strings
- Watch: sessions authenticated as the default "MSP Support" Take Control account
- Restrict: N-central console access to VPN or IP-allowlisted networks only
Patch Adoption Lagged Even After a Public Warning
The August incident offers a useful, if uncomfortable, data point on how quickly MSPs actually patch critical infrastructure once a vendor sounds the alarm. Huntress tracked patch adoption across its own partner and customer base in near real time, and the numbers moved slower than anyone watching would want.
| Timestamp (Aug. 2026) | Reachable Cloud Servers Unpatched | Reachable Self-Hosted Servers Unpatched | Overall Unpatched (Reachable) |
|---|---|---|---|
| Aug 3, 12:45 AM ET | 55.6% | Not separately reported | Majority still exposed |
| Aug 3, 2:15 PM ET | Nearly all patched | 28.6% | 13.6% |
Cloud-hosted instances closed the gap fast, largely because N-able could push mitigations centrally. Self-hosted, on-premises servers lagged well behind, still sitting at 28.6% unpatched roughly 14 hours after the first data point. That gap between hosted and self-hosted patch speed is the same gap that let the September cluster catch a “fully patched” customer environment off guard: patched against the August bugs did not mean patched against bugs nobody had found yet.
This Isn’t N-central’s First Time on a Watchlist
N-central’s 2026 run of hotfixes follows a 2025 incident that put the product on the federal government’s radar. CVE-2025-8875, an N-central vulnerability, was added to the Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog on August 13, 2025, confirming exploitation in the wild rather than a theoretical risk. A companion flaw, CVE-2025-8876, an improper input validation bug enabling OS command injection, was patched in the same release, N-central 2025.3.1. N-able confirmed at the time that its investigations had turned up evidence of that earlier exploitation in a limited number of on-premises environments, while stating it had not seen evidence of exploitation in hosted cloud environments, according to reporting on the incident.
Read against that backdrop, 2026’s four-hotfix stretch looks less like a one-off scare and more like a pattern: a widely deployed RMM platform, a security disclosure program that keeps surfacing critical bugs, and a gap between vendor confirmation and independent researcher findings that keeps repeating itself year over year.
Why RMM Platforms Keep Ending Up in the Crosshairs
The reason attackers target tools like N-central instead of individual businesses comes down to leverage. An RMM platform exists specifically to give one login the ability to touch every endpoint a provider manages, which is exactly the property that turns a single vendor vulnerability into a supply-chain event. The clearest precedent remains the July 2021 Kaseya VSA incident, in which the REvil ransomware group exploited a zero-day in Kaseya’s own RMM software to push ransomware downstream. Kaseya’s CEO said at the time that between 50 and 60 of the company’s roughly 37,000 customers were compromised, and through those MSPs, an estimated 1,500 small and mid-sized businesses worldwide ended up affected. REvil’s initial ransom demand for a universal decryptor reportedly reached around $70 million, a figure widely described as unprecedented for a single ransomware campaign at that time.
N-able’s own account of the August N-central incident echoes the same mechanics on a smaller confirmed scale: a compromised N-central server, Huntress wrote, can be used to run scripts, push tools, and open remote sessions across every downstream endpoint it manages. The company said it had confirmed exploitation impacting one organization in its own customer base as of its August update, while cautioning it was continuing to hunt for related activity across its wider telemetry.
RMM Supply-Chain Incidents in Historical Context
| Incident | Vendor / Product | Vulnerability Type | Confirmed Impact | Outcome |
|---|---|---|---|---|
| July 2021 | Kaseya / VSA | Zero-day RCE chain | ~50-60 of ~37,000 MSP customers hit; ~1,500 downstream businesses affected | REvil demanded ~$70M for a universal decryptor |
| Aug 2025 | N-able / N-central | CVE-2025-8875 (added to CISA KEV Aug 13, 2025), CVE-2025-8876 (OS command injection) | Confirmed exploitation in a limited number of on-prem environments | Patched in N-central 2025.3.1 |
| Aug 2026 | N-able / N-central | CVE-2026-18556, CVE-2026-18577 (unauthenticated console access) | Confirmed exploitation impacting at least one Huntress customer | Patched in Hotfix 1 and Hotfix 2 |
| Sept 2026 | N-able / N-central | CVE-2026-86206, CVE-2026-86207, CVE-2026-86218 (CVSS 10.0) | Reported active exploitation per MSPGeek post and N-able incident page; not confirmed in official release notes | Patched in Hotfix 3 and Hotfix 4 |
Competitive Landscape: N-central Among RMM Platforms
N-central competes for MSP business against platforms including ConnectWise Automate, Datto RMM (also under the Kaseya umbrella since Kaseya acquired Datto), Atera, and Syncro. None of those competitors has a documented CVSS 10.0 incident of this scale reported in the sources reviewed for this piece, though that comparison should be read carefully: absence of a similarly severe disclosed CVE this month is not the same as an absence of risk, since RMM tools across the industry share the same fundamental exposure by design. Any platform built to give one console centralized control over thousands of client endpoints inherits the same blast-radius math that turned the Kaseya and N-central incidents into industry case studies rather than routine patch notes.
What differentiates N-central’s 2026 story from a typical single-CVE disclosure is the compressed timeline. Three separate researchers, two of them apparently working independently of each other, surfaced three distinct vulnerability clusters inside the same five-week window, on the same product, at the same time N-able was actively trying to close the previous gap. That pace of discovery suggests the product drew heightened scrutiny from the security research community once the August flaw became public, a common dynamic once a widely used product is shown to have one serious hole.
Market and Business Impact for MSPs
For managed service providers, the practical cost of this month isn’t just the patching labor, it’s the trust conversation with clients. Every MSP running N-central now has to explain to end customers why a tool meant to secure their environment became, for a window of days, a potential entry point into it. Cyber insurance underwriters have grown increasingly attentive to RMM exposure since Kaseya, and a repeat pattern of critical N-central disclosures inside a single product cycle is the kind of signal that shows up in renewal questionnaires and premium calculations.
There’s also a straightforward productivity cost. Huntress’s own recommendation, that organizations consider temporarily taking an internet-exposed N-central server offline until Hotfix 4 is applied and network controls are locked down, is not a trivial ask for an MSP that depends on that console to service dozens of clients simultaneously. Every hour N-central is dark is an hour of degraded service delivery across every downstream account it touches.
What Security Researchers Are Telling N-central Customers to Do Now
- Apply N-central 2026.3 Hotfix 4 (build 2026.3.1.14) immediately on any on-premises deployment, including servers already updated to Hotfix 3
- Confirm hosted (NCOD) instances show the patched build, since N-able says these were updated automatically
- Audit user accounts for unexpected creations, especially email addresses appended with “.invalid” or containing subtle domain spoofing
- Review envoy_proxy_HTTPS.log and syslog ncentraldms for API manipulation and URL-encoded endpoint anomalies
- Restrict all inbound access to the N-central console to VPN or IP-allowlisted networks, even after patching
- Review Take Control session logs for logins under the default “MSP Support” account tied to IP addresses outside expected ranges
Huntress has said it will continue updating its incident page as new information becomes available, and organizations that suspect compromise should assume an attacker with console access could have pushed scripts or opened remote sessions to any endpoint N-central manages, not just the appliance itself.
What Happens Next: Five Predictions
CVE-2026-86218 likely lands on the CISA KEV catalog. Given that both an N-able employee’s own Discord post and the company’s Active Incident page reportedly described active exploitation, and given the CVE-2025-8875 precedent from last year, federal confirmation of in-the-wild exploitation looks like a matter of time rather than a possibility.
More hotfixes are coming. A product that has drawn three independent researcher disclosures in five weeks has demonstrated it’s currently a live target for the security research community, and that kind of attention rarely stops at the fourth finding.
Expect a push toward mandatory network segmentation for RMM consoles. Huntress’s blunt advice to consider taking exposed servers offline entirely is likely to harden into a standing best practice recommendation across the MSP community, not just a temporary emergency measure.
Insurance and compliance questionnaires will start naming N-central explicitly. The Kaseya 2021 incident changed how cyber insurers underwrite MSP risk. A repeat critical-vulnerability pattern on a major competing platform is the kind of event that gets written into renewal terms.
Vendor communication practices will face renewed scrutiny. The gap between N-able’s official “no confirmations” language and the more direct exploitation claims attributed to its own staff member and incident page is likely to become a talking point in how RMM vendors are expected to disclose active exploitation going forward.
Frequently Asked Questions
What is CVE-2026-86218?
It’s a pre-authentication remote code execution vulnerability in N-able’s N-central remote monitoring and management platform, disclosed September 6, 2026, and rated CVSS 10.0, the maximum possible severity score. It’s classified under CWE-96, static code injection, and requires no login or user interaction to exploit.
Is N-central CVE-2026-86218 being actively exploited?
Accounts differ. N-able’s official Hotfix 4 release notes say the company has no confirmation of exploitation in production environments. However, a post from an N-able employee in an MSPGeek Discord thread and N-able’s own Active Incident page reportedly described the vulnerability as having already been observed being exploited in the wild, according to Huntress’s reporting.
Which N-central versions are affected?
All N-central builds prior to 2026.3.1.14 are affected, including servers already running Hotfix 3 (build 2026.3.1.13). The fix ships in Hotfix 4 (2026.3.1.14).
How do I patch against CVE-2026-86218?
On-premises customers should upgrade to N-central 2026.3 Hotfix 4 immediately using N-able’s official release notes and upgrade instructions. Hosted (NCOD) customers do not need to take action, as N-able says those instances were already patched.
Has N-central had security problems before 2026?
Yes. In 2025, CVE-2025-8875 was added to CISA’s Known Exploited Vulnerabilities catalog after confirmed active exploitation, alongside a companion flaw, CVE-2025-8876, an OS command injection bug. Both were fixed in N-central 2025.3.1.
What is the connection to the 2021 Kaseya VSA attack?
Kaseya VSA is a comparable RMM platform that suffered a 2021 zero-day exploit by the REvil ransomware group, affecting an estimated 1,500 downstream businesses through roughly 50-60 compromised MSPs, with a reported $70 million universal ransom demand. It remains the reference case for why RMM software carries outsized supply-chain risk, the same dynamic security researchers are pointing to with the N-central disclosures.
What should MSPs do right now beyond patching?
Security researchers recommend auditing user accounts for suspicious creations, reviewing appliance logs for API manipulation, restricting console access to VPNs or allowlisted IP ranges, and reviewing Take Control session history for unexpected logins, even after applying the latest hotfix.
Why does an RMM vulnerability matter beyond the vendor itself?
RMM platforms are built to give one login centralized control over every endpoint a managed service provider oversees for its clients. A single compromised RMM server can therefore become a launch point into dozens or hundreds of unrelated downstream networks at once, which is what makes these tools disproportionately attractive targets compared to a typical single-company breach.




