Exploited in the wild N-able N-central rce N-central 2026.3 HF4 N-able auth-bypass
N-able patches max severity N-central flaw amid ongoing attacks
CVE Tools coverage
N-able has issued an emergency hotfix for a maximum-severity remote code execution vulnerability, identified as CVE-2026-86218">CVE-2026-86218, in its N-central platform. This flaw allows unauthenticated attackers to execute malicious code on exposed systems. While N-able has not confirmed widespread production exploitation, security firm Huntress has flagged the issue as part of ongoing active attack campaigns involving related vulnerabilities. Organizations using N-central are advised to install N-central 2026.3 HF4 immediately to mitigate the risk.