CISA Warns of N-able N-central RCE Vulnerability Exploited in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

The Cybersecurity and Infrastructure Security Agency has added a maximum-severity flaw in N-able’s N-central remote monitoring and management platform to its Known Exploited Vulnerabilities catalog, confirming that attackers are actively abusing the bug against real-world targets.

The vulnerability, tracked as CVE-2026-86218, carries a perfect CVSS score of 10.0 and allows unauthenticated remote code execution, making it one of the most dangerous flaws to hit the managed service provider ecosystem this year.

CISA classifies CVE-2026-86218 as a static code injection vulnerability tied to CWE-96, meaning attackers can inject malicious directives into statically saved, executable code on the N-central server.

N-able N-central RCE Vulnerability

Because the flaw requires no authentication or user interaction, any threat actor with network access to an exposed N-central instance could run arbitrary commands, giving them a foothold not just into the platform itself but into every downstream endpoint an MSP manages through it.

The bug was reported to N-able through the company’s responsible disclosure program and affects all on-premises N-central builds prior to version 2026.3.1.14, spanning the 2025.4, 2026.1, 2026.2, and 2026.3 release lines, including systems that had already applied earlier hotfixes in the same release cycle.

N-able shipped Hotfix 4 for N-central 2026.3 on September 5-6, 2026, bringing on-premises deployments to build 2026.3.1.14. This marked the fourth emergency hotfix the company issued within five weeks, following earlier fixes for separate authentication bypass and RCE issues tracked as CVE-2026-86206 and CVE-2026-86207.

Hosted N-central customers did not need to take action since N-able patched those environments server-side, but on-premises administrators were urged to upgrade immediately.

While N-able initially stated it had no confirmation of exploitation in production environments, CISA’s KEV listing and independent research from Huntress indicate otherwise, with at least one customer’s N-central instance reportedly compromised on September 4, two days before the patch shipped. CISA added the flaw to its catalog on September 8, 2026.

Under Binding Operational Directive 26-04, federal civilian agencies running affected N-central instances have until September 11, 2026, to apply mitigations, and CISA is requiring forensic triage on any system found exposed prior to patching. The directive also instructs agencies to follow BOD 26-04 guidance for cloud services or discontinue use of the product entirely if mitigations cannot be applied in time.

Given N-central’s widespread use among MSPs managing thousands of downstream client networks, security teams should treat this as an urgent, organization-wide priority rather than a routine patch cycle.

Administrators should upgrade on-premises instances to 2026.3.1.14 immediately, audit internet exposure of their N-central servers, and review logs for signs of compromise dating back to early September, since a compromised RMM server can serve as a single point of entry into an entire client base.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

The post CISA Warns of N-able N-central RCE Vulnerability Exploited in the Wild appeared first on Cyber Security News.