← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 7, 2026 · 07:08via CyberPress

Critical N-able N-central Flaw Enables Unauthenticated Pre-Auth Remote Code Execution

Brief

N-able has issued an urgent security update for a critical vulnerability in its N-central remote monitoring and management (RMM) platform that could let an unauthenticated attacker execute code on a vulnerable server before logging in.

Tracked as CVE-2026-86218, the issue is fixed in N-central 2026. 3 Hotfix 4, build 2026.

  • 1.
  • N-central is used by managed service providers and IT teams to administer endpoints and customer environments from a central console.

A pre-authentication remote code execution flaw is especially serious in that role: exploitation would not require valid N-central credentials, potentially giving an attacker a foothold on the management server that can span the administered infrastructure.

Read more on CyberPress