Security company N-able has issued an emergency hotfix to address a critical zero-day vulnerability in its N-central platform.
The pre-authentication flaw in N-central, tracked as CVE-2026-86218, could enable an attacker to achieve remote code execution. The vulnerability has a severity score of 10, the highest on the scale, according to researchers. The N-central platform combines unified endpoint management with remote monitoring and management.
The hotfix is the fourth one released in a row by the vendor after researchers disclosed a series of prior flaws in the platform. N-able is urging all customers running on-premises N-central deployments to immediately upgrade to this latest version, according to a security advisory from the company.
Researchers from Huntress previously reported an authentication bypass that impacted N-central environments. The activity was related to two chained vulnerabilities, including an access control filter bypass tracked as CVE-2026-86206 and an authentication bypass, tracked as CVE-2026-86207.
The activity Huntress identified last Friday involved an unauthorized intrusion in an organization with a fully patched N-central instance, according to Michael Tigges, principal tactical response analyst at Huntress.
“We observed an anomalous/non-existent user creating an additional user account named to blend in with the rest of the appliance’s users,” Tigges said. The attacker installed Cloudflared, which is a Cloudflare tunneling application.
CISA catalog listing
In August, N-able issued a patch to address CVE-2026-18577, a pre-authentication vulnerability in N-central that was being exploited in the wild, according to researchers at Rapid7. An incomplete patch had been issued for CVE-2026-18556.
Rapid7 warned that a successful compromise of N-central could provide an attacker with extensive administrative privileges, which enables wide access to downstream managed systems.
Both vulnerabilities were added to the Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog in August.