CVE Tools

N-able patches critical N-central zero-day exploited in the wild (CVE-2026-86218)

Help Net SecurityBy Sinisa Markovic

Reported exploitedN-central

Our summary

N-able has issued an urgent security update for its N-central remote monitoring and management platform, addressing a critical vulnerability identified as CVE-2026-86218. This flaw allows for pre-authenticated remote code execution on the N-central server, posing a significant risk to both hosted and on-premises deployments. While the vendor's initial public advisory did not confirm active exploitation, subsequent customer notifications explicitly stated that the vulnerability was observed being exploited in the wild, characterizing it as a zero-day issue. Affected organizations are advised to upgrade immediately to N-central 2026.3 Hotfix 4 (build 2026.3.1.14) to mitigate the threat.

Read at Help Net Security

Help Net Security publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store