Cyber Resilience
← All news
Corroborated

N-able patches critical N-central zero-day exploited in the wild (CVE-2026-86218)

Our takeN-able shipped an emergency hotfix for CVE-2026-86218, a pre-auth RCE in N-central confirmed exploited in the wild. Patch the server at once if you run it; otherwise confirm your MSP has applied the update.
Sources (2)
What this means for you — Security leader:If you self-host N-central, apply the emergency hotfix for CVE-2026-86218 immediately and scan for signs of pre-auth RCE.
What this means for you — Lean IT orgs:If your IT provider uses N-central to manage your systems, ask them today whether they have applied the hotfix for this critical remote code execution flaw.
What this means for you — MSP:Deploy the N-central hotfix for CVE-2026-86218 to all instances without delay; treat any internet-exposed server as potentially compromised and investigate.
What this means for you — Researcher:N-able published an emergency hotfix addressing pre-auth RCE (CVE-2026-86218) confirmed exploited in the wild.