Critical N-able N-central Flaw Enables Unauthenticated Pre-Auth Remote Code Execution
Brief
N-able has issued an urgent security update for a critical vulnerability in its N-central remote monitoring and management (RMM) platform that could let an unauthenticated attacker execute code on a vulnerable server before logging in.
Tracked as CVE-2026-86218, the issue is fixed in N-central 2026. 3 Hotfix 4, build 2026.
- 1.
- N-central is used by managed service providers and IT teams to administer endpoints and customer environments from a central console.
A pre-authentication remote code execution flaw is especially serious in that role: exploitation would not require valid N-central credentials, potentially giving an attacker a foothold on the management server that can span the administered infrastructure.
