Security researchers warned the company of unusual threat activity in a recently updated N-able environment.
Security company N-able has issued an emergency hotfix to address a critical zero-day vulnerability in its N-central platform.
The pre-authentication flaw in N-central, tracked as<a href="https://nvd.nist.gov/vuln/detail/cve-2026-86218″ rel=”nofollow noopener” target=”_blank”>CVE-2026-86218, could enable an attacker to achieve remote code execution. The vulnerability has a severity score of 10, the highest on the scale, according to researchers. TheN-central platform combines unified endpoint management with remote monitoring and management.
The hotfix is the fourth one released in a row by the vendor after researchers disclosed a series of prior flaws in the platform. N-able is urging all customers running on-premises N-central deployments to immediately upgrade to this latest version,according to a security advisoryfrom the company.
Researchers from Huntresspreviously reported an authentication bypassthat impacted N-central environments. The activity was related to two chained vulnerabilities, including an access control filter bypass tracked asCVE-2026-86206and an authentication bypass, tracked asCVE-2026-86207.
The activity Huntress identified last Friday involved an unauthorized intrusion in an organization with a fully patched N-central instance principal tactical response analyst at Huntress
“We observed an anomalous/non-existent user creating an additional user account named to blend in with the rest of the appliance’s users,” Tigges said. The attacker installed Cloudflared, which is a Cloudflare tunneling application.
CISA catalog listing
In August, N-able issued a patch to addressCVE-2026-18577, a pre-authentication vulnerability in N-central that was being exploited in the wild, according toresearchers at Rapid7. An incomplete patch had been issued forCVE-2026-18556.
Rapid7 warned that a successful compromise of N-central could provide an attacker with extensive administrative privileges, which enables wide access to downstream managed systems.
Both vulnerabilities were added to the Cybersecurity and Infrastructure Security Agency’sKnown Exploited Vulnerabilitiescatalog in August.
Filed Under:Vulnerability,Cyberattacks
