N-able N-central CVE-2026-86218: Pre-Auth RCE on the MSP Brain (CVSS 10)

By George Bailey   Published: 09/16/26   Updated: 09/16/26   3 min read

Your MSP’s remote-management brain just became a pre-auth takeover story. A maximum-severity flaw in on-prem N-able N-central lets an unauthenticated attacker run code on the server that manages every customer endpoint you touch.

If you still run N-central below the fixed hotfix build, treat this as an incident triage — not a weekend patch window.

What happened

On September 6, 2026, N-able shipped Hotfix 4 (build 2026.3.1.14) for a critical static code-injection bug tracked as CVE-2026-86218 (CVSS 10.0). The flaw sits in a public-facing application endpoint and allows remote code execution before authentication.

Researchers and vendors note it can be chained with related authentication-bypass issues (CVE-2026-86206 and CVE-2026-86207, fixed earlier in Hotfix 3) so adversaries can skip console login and mint attacker-controlled admin accounts. Exploitation was observed before public disclosure. CISA added CVE-2026-86218 to KEV on September 8, 2026.

Hosted N-central Online environments were patched by N-able. On-premises servers remain the operator’s job.

Why it matters

N-central is the MSP control plane: agents, scripts, credentials, and remote shells into customer estates. Compromising it is how a single internet-facing console becomes a multi-tenant ransomware or data-theft amplifier.

Pre-auth RCE plus account-creation bypasses means “we patched later” is not the same as “we were never owned.” Hunt first if the box was reachable.

What to do first

Details

Hunt / verify

Sources

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.