Back to blog
CVEMSPRCE

N-able N-central CVE-2026-86218: CVSS 10 Pre-Auth RCE Exploited, One Month After August Flaw

Published on 2026-09-105 min readCleanIssue

> TL;DR: CVE-2026-86218 (CVSS 10.0) is a static code injection in N-able N-central enabling pre-authentication remote code execution — fixed in N-central 2026.3 Hotfix 4, released September 5, 2026. N-able has told customers the flaw "has been observed being exploited in the wild," and CISA added it to the KEV catalog with a September 11 deadline. Meanwhile, Huntress is investigating a fully patched customer N-central production environment compromised on September 4 — unable to determine whether the vector is this flaw or the two chainable vulnerabilities patched the same day (CVE-2026-86206 and CVE-2026-86207), which let an unauthenticated attacker create an attacker-controlled System Administrator account.

A platform under continuous pressure

This is the second major N-central episode in a month, after August's authentication bypass (CVE-2026-18577) where attackers hijacked MSP RMM servers and deployed Cloudflare tunnels for persistence. This season's pattern is identical: a platform administering thousands of machines becomes the priority target, because one compromise opens access to everything managed downstream.

watchTowr reproduced CVE-2026-86218 and described the stakes precisely: the code execution allows changes in N-central that "can propagate across all connected systems." Compromise an MSP's server and you reach every endpoint of every client — hence ransomware gangs' longstanding interest in this product.

The detail that should alarm you: a patched server compromised

The most unsettling part is the Huntress-investigated incident: a fully patched N-central production environment compromised on September 4. Vector attribution remains uncertain (insufficient historical logging on the appliance), with three candidates — CVE-2026-86218, or the CVE-2026-86206/86207 pair (authentication bypass then rogue System Administrator account creation, found by Rapid7). Three operational consequences:

  • Patching does not close the incident. If the server was exposed before September 5, treat it as potentially compromised and investigate — do not merely update.
  • Appliance logs limit the investigation. Without centralized log retention, vector attribution is impossible — true for N-central and for any appliance in your stack.
  • Admin account creation is the simplest IoC to hunt: unknown administrator accounts, recent creations, unexplained elevations.
  • What to do

  • Apply N-central 2026.3 Hotfix 4 (and Hotfix 3 if not deployed) to all instances — including those managed on behalf of customers.
  • Pull admin interfaces off the Internet: N-central portal access should only traverse a controlled path (VPN, IP allowlist).
  • Hunt pre-existing compromises: unknown admin accounts, anomalous Take Control sessions, modified deployment scripts, unusual outbound connections from the appliance.
  • Check downstream: every endpoint managed by a possibly exposed instance deserves inspection — propagation is what makes this product's risk severe.
  • Centralize logs from administration consoles (RMM, PAM, hypervisors) into your SIEM: the Huntress incident shows what their absence costs.
  • The broader lesson

    Concentrated administration platforms — RMM, PAM, endpoint management consoles, and ultimately any multi-tenant SaaS back office — have become strategic assets for attackers, exactly like IdPs. Their security is not just versioning: restricted exposure, central logging, account-creation detection, downstream monitoring. If your product is that kind of console for your customers, those four requirements are part of your security promise — and belong in your audits.

    Building HR, payroll, or recruiting software? CleanIssue performs security audits for HR SaaS in real-world conditions, no source code access needed. For a first read of your exposure, start with an external review of your application.

    Related articles

    Three adjacent analyses to keep exploring the same attack surface.

    CVEMSP

    PaperCut NG/MF: Two Zero-Days Chained for Unauthenticated RCE, Incomplete Patches, and a CISA Deadline

    Flaws in the PaperCut NG and MF print management software are exploited in real attacks: an authentication bypass (CVE-2026-81578) followed by unsafe dynamic class loading (CVE-2026-82078) leads to arbitrary Java code execution without an account. Two successive emergency patches, patch bypasses already identified against the latest fully patched version, and a CISA KEV entry with a September 14, 2026 deadline.

    2026-08-31 · 7 min read
    CVEenterprise

    N-able N-central CVE-2026-18577: MSP servers hijacked via auth bypass, persisted with Cloudflare tunnels

    An authentication bypass (CVE-2026-18577) in N-able's N-central RMM platform let attackers gain remote administrative access and reach customer endpoints. They registered Cloudflare tunnels as services for persistent, firewall-evading access. The first fix was incomplete. Fixed in build 2026.3.1.7.

    2026-08-03 · 6 min read
    GitLabCVE

    GitLab CVE-2026-85706: Unauthenticated Arbitrary File Read (CVSS 10), Scanned Within Hours

    A path traversal in the repository commits API (CVE-2026-85706, CVSS 10.0) lets an unauthenticated user read arbitrary files from the GitLab server — logs and configuration holding credentials and secrets — as soon as one public project exists. Active probes observed September 11; CISA KEV with a September 14 deadline. Fixes: 19.1.8, 19.2.6, 19.3.2, also covering an EE deserialization flaw (CVE-2026-87719, 9.9).

    2026-09-12 · 5 min read

    Sources

    Related services

    If this topic maps to a real risk in your stack, these are the most relevant CleanIssue audits.

    Need an external review of your HR SaaS?

    Share your product, stack, and client context. We will come back with the right review scope.

    Discuss your audit