Vulnerabilities

N-able Patches Critical N-central RCE as Fourth Hotfix Lands in Five Weeks

N-able released a fourth emergency hotfix for its N-central platform over the weekend, closing a pre-authentication remote code execution flaw that an attacker can trigger against any console reachable from the internet with no credentials at all. The fix is N-central 2026.3 Hotfix 4, build 2026.3.1.14 and the vulnerability is CVE-2026-86218. Anyone who applied Hotfix 3 the day before is still exposed.

N-central is the remote monitoring and management console that managed service providers and internal IT teams use to administer client servers, workstations and network devices from one place. It carries standing administrative reach into every endpoint it manages. That is the product working as designed.

Four Hotfixes Since 2 August

The sequence started on 31 July when N-able’s Adlumin MDR service flagged unusual activity in a customer environment and identified a threat actor exploiting a then-unknown N-central flaw. N-able registered CVE-2026-18556 and shipped Hotfix 1, build 2026.3.1.7, on 2 August. Analysis that same morning exposed a second route to the same weakness, registered as CVE-2026-18577.

Rapid7 describes CVE-2026-18577 as the product of an incomplete fix for CVE-2026-18556. CISA added it to the Known Exploited Vulnerabilities catalogue on 3 August and gave federal civilian agencies until 6 August to remediate, a three-day window rather than the usual 14 under Binding Operational Directive 26-04. CVE-2026-18556 followed into the catalogue on 5 August. N-able shipped Hotfix 2, build 2026.3.1.10, on 6 August after continued monitoring surfaced a related attack path.

Hotfix 3 arrived on 5 September for CVE-2026-86206 and CVE-2026-86207, two authentication bypass flaws N-able rates as high severity and describes as granting full access to the platform. Hotfix 4 followed roughly a day later. Four patches in five weeks, three of them superseding the one before.

Two of those CVEs exist only because an earlier fix did not reach the root cause. Worth remembering the next time a vendor advisory lands with a same-day patch attached and the matter is presented as closed.

N-able and Huntress Do Not Agree on Whether It Is Being Exploited

The HF4 release notes say the flaw was responsibly disclosed by a third party through N-able’s security disclosure programme and that the company has “no confirmations that this vulnerability has been exploited in production environments.” Huntress describes the same CVE as an “actively exploited pre-auth RCE zero-day” carrying a CVSS score of 10.0.

That is a wide gap for one vulnerability and both parties have something riding on which description sticks. N-able sells the platform. Huntress sells detection and response and an actively exploited zero-day in an RMM console is useful marketing for a company whose product catches exactly that. Read both with that in mind.

What they agree on is more useful than what they dispute. Huntress found a compromised N-central server inside a customer environment that had already been patched, and says it cannot determine which vulnerability was used because the logs on that server had rotated. An intrusion on a patched console with no attributable entry point is the practical worst case here, whichever CVE it turns out to be.

The August Attacks Used Features, Not Malware

The exploitation CISA documented in August involved no custom tooling. After bypassing authentication, the attackers used N-central’s built-in Take Control feature to reach managed endpoints, then deployed Cloudflare Tunnel, the legitimate cloudflared utility to hold persistent remote access.

N-able published indicators for that activity, a file named svchost.exe in a device user’s documents folder and a registered service called Cloudflared. Huntress recorded a malicious connection made under “MSP Support”, the default username attached to legitimate Take Control sessions with traffic arriving from Mullvad and NordVPN exit nodes.

To a monitoring console, all of this looks like an administrator doing administration. There is no malware to match and no unfamiliar binary to flag. The only signal is that the administrator is not who the console thinks they are.

Nearly 1,500 Consoles Are Still Reachable From the Internet

Shadowserver tracks close to 1,500 internet-facing N-central servers, most of them in the United States and Europe. N-able says hosted NCOD instances have already been patched which puts the residual exposure almost entirely on on-premises deployments.

Huntress figures cited by The Register show how uneven that split was during the August wave. By 3 August nearly all cloud-hosted instances had been updated while 28.6 percent of observed self-hosted servers were still vulnerable and still exposed. That was a flaw already sitting in the CISA catalogue with a three-day federal deadline attached.

Patch, Then Assume You Were Late

Apply Hotfix 4, build 2026.3.1.14. Hotfix 1, 2 and 3 do not cover CVE-2026-86218 and N-able has been explicit that systems on HF3 remain vulnerable to it.

Audit the N-central user list for administrative accounts nobody created. On 5 September Huntress published a proof of concept for a chain involving CVE-2026-86207 that lets an attacker create unauthorised administrative accounts and flagged addresses ending in .invalid as an indicator. Restrict inbound network access to the console while you work through it.

Do not start the log review at the hotfix date. Exploitation of the August pair began on 31 July, two days before the first advisory existed. Sixty days back is a more honest starting point than the day you patched.

For essential and important entities under Cybersäkerhetslagen (SFS 2025:1506), in force since 15 January 2026, a compromised RMM console with administrative reach into client estates will meet the threshold for a significant incident on most readings. The cascade is an early warning to MCF (formerly MSB) within 24 hours, a full notification within 72 hours and a final report within one month. That 24-hour clock starts when you become aware, not when the investigation is finished.

References

  1. N-able Patches Max Severity N-central Flaw Amid Ongoing Attacks
  2. N-central 2026.3 Hotfix 4, CVE-2026-86218
  3. N-central 2026.3 Hotfix 3, CVE-2026-86206 and CVE-2026-86207
  4. CVE-2026-18577: N-able N-central Authentication Bypass Exploited in the Wild
  5. CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises
  6. Feds Get 3 Days to Patch N-able God Mode Flaw Under Active Exploit

This post is also available in: Svenska

Erik Berg

Erik Berg is CTO and Principal Security Architect at eBuilder Security, with more than a decade in blue team security operations across the private and public sectors, and a focus on emerging threats including the security risks that come with AI.