N-able releases an emergency hotfix for a maximum-severity remote code execution (RCE) vulnerability affecting its N-central remote monitoring and management (RMM) platform. The issue is described as a critical flaw that could allow attackers to execute code remotely against the N-central server.
Multiple outlets report that the vulnerability is being exploited in the wild. Help Net Security identifies it as CVE-2026-86218 and notes that N-able characterizes it as pre-authenticated RCE, meaning an attacker does not need full authentication to trigger the problem. Bleeping Computer reports N-able has deployed an emergency hotfix for what it calls a max-severity N-central flaw amid ongoing attacks.
Help Net Security adds that N-able fixes the vulnerability by releasing Hotfix 4 for N-central 2026.3, updating the software build to 2026.3.1.14. The reporting frames N-central as a product used by managed service providers (MSPs), which increases the potential impact if exploited systems are not updated promptly.