IT management software vendor N-able has released an urgent hotfix for a critical, actively targeted vulnerability in its N-central endpoint management platform that could allow unauthenticated remote code execution.
A Zero-Day Uncovered While Patching Other Flaws
The vulnerability, tracked as CVE-2026-86218 and rated a maximum CVSS score of 10, was discovered after N-able patched two related issues in N-central, CVE-2026-86206 and CVE-2026-86207. N-able says the newly disclosed flaw “could allow pre-authenticated access to the N-central server if exploited,” and that the fix, delivered as the 2026.3 HF4 hotfix, supersedes the earlier patches.
Customers on N-able’s hosted N-central environments do not need to take action, since the vendor deployed the fix server-side. Organizations running on-premises N-central instances are urged to apply the hotfix immediately.
Signs of Active Scanning and Possible Exploitation
N-able says it has observed scanning activity targeting the vulnerability originating from the IP range 23.234.64.0/18 and is advising administrators to review logs for connections from that range, as well as to check for any newly created user accounts they do not recognize. The company says it currently has no confirmation the flaw has been exploited in production environments, but that unpatched systems remain at risk.
Cybersecurity firm Huntress, which had already flagged the two earlier N-central bugs as potentially chained together in the wild to bypass authentication, said it observed attacks targeting N-central’s underlying API and appliance logs beginning Sept. 4. Huntress noted that limited historical logging on the appliance makes it difficult to confirm with certainty which specific vulnerability an attacker used to achieve a given compromise, or to rule out the use of other flaws entirely.

Leave a Reply