Active Exploitation of Vulnerability in N-Able N-Central
9 September 2026
Attackers are exploiting a critical vulnerability in N-Able N-Central remote management and monitoring tool to execute code remotely without authentication. Patch immediately.
Background
N-Able has released security updates to address a critical vulnerability (CVE-2026-86218) affecting N-Able N-Central. This vulnerability has a Common Vulnerability Scoring System (CVSS v3.1) score of 9.8 out of 10.
Impact
Successful exploitation of this vulnerability could allow an unauthenticated attacker to achieve remote code execution on affected N-Central systems.
Known Exploitation
This vulnerability is reportedly being actively exploited.
Affected Products
This vulnerability affects N-Central versions before 2026.3.1.14.
Recommendations
Users and administrators of affected products are advised to update to the latest version immediately.
References
https://nvd.nist.gov/vuln/detail/CVE-2026-86218 (opens in new tab)
