IT software firm N-able has rolled out an urgent fix for an unauthenticated remote code execution (RCE) vulnerability in its N-central endpoint management platform that has been exploited as a zero-day.
Tracked as CVE-2026-86218 (CVSS score of 10/10), the security defect was discovered after N-able patched two other flaws in N-central, namely CVE-2026-86206 and CVE-2026-86207
“This critical zero-day vulnerability, CVE-2026-86218, could allow pre-authenticated access to the N-central server if exploited,” N-able warns.
While no action is required for N-central hosted environments, as the patches were deployed server-side, users of on-premises N-central instances should immediately apply the 2026.3 HF4 hotfix, the company says.
“Review your logs for scanning activity. We’ve observed scans originating from the IP range 23.234.64.0/18 attempting to exploit this vulnerability. Check your logs for any connections from this range,” N-able also notes.
Administrators are also advised to check their deployments for newly created user accounts they don’t recognize.
“At this time, we have no confirmations that this vulnerability has been exploited in production environments, but unpatched systems remain at risk,” N-able says.
The hotfix for the exploited zero-day supersedes the previously released patches for CVE-2026-86206 and CVE-2026-86207, two bugs that Huntress flagged as potentially chained together in the wild to bypass authentication and compromise N-central production environments.
“However, due to limited historical logging available directly on the appliance, we cannot definitively confirm which specific exploit the threat actor used to achieve their compromise, nor can we rule out the use of alternative vulnerabilities,” Huntress said on Saturday.
The cybersecurity firm observed attacks targeting N-central’s underlying API and appliance logs starting on September 4, 2026.
Related: Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits
Related: Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
Related: Modified ScreenConnect Clients Used in Worm-Like Campaign
Related: Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites
