CVE Tools

N-able patches max severity N-central flaw amid ongoing attacks

BleepingComputerBy Sergiu Gatlan

Reported exploitedN-able N-centralN-central 2026.3 HF4

Our summary

N-able has issued an emergency hotfix for a maximum-severity remote code execution vulnerability, identified as CVE-2026-86218">CVE-2026-86218, in its N-central platform. This flaw allows unauthenticated attackers to execute malicious code on exposed systems. While N-able has not confirmed widespread production exploitation, security firm Huntress has flagged the issue as part of ongoing active attack campaigns involving related vulnerabilities. Organizations using N-central are advised to install N-central 2026.3 HF4 immediately to mitigate the risk.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store