CVE-2026-86218 is a maximum severity, unauthenticated remote code execution flaw in N-able N-central that hands attackers full admin control of the RMM console. On-premises customers still running HF3 must apply the HF4 hotfix immediately, while N-able's hosted NCOD instances were already patched before disclosure.
Read the full story: N-able N-central Hit by CVSS 10.0 Pre-Auth RCE Flaw →
Transcript
A brand new N-able N-central vulnerability just scored a perfect 10 out of 10 on the CVSS scale. That's CVE-2026-86218, and it lets an attacker with no login at all seize full god-mode control of the console. Here's why that matters. N-central isn't just one company's software, it's what managed service providers use to run thousands of client networks from a single dashboard. Compromise that console and you don't just own the MSP, you own every customer behind it. This is the second major N-central incident in a month, after an earlier flaw got federal agencies an unusually short three day patch deadline. If you're running N-central on-premises, hotfix HF4 is not optional. Cloud customers are already covered.