N‑able issues hotfix for critical N-central RCE
🔒 N-able has released a hotfix addressing a critical pre-authentication remote code execution vulnerability, CVE-2026-86218, in its N-central monitoring and management platform. The flaw, given a maximum CVSS score of 10, impacts N-central versions before 2026.3.1.14 and could allow unauthenticated code execution on the server. N-able patched the issue in N-central 2026.3 Hotfix 4 (build 2026.3.1.14) and reports no evidence of in-the-wild exploitation. This follows several recent high-severity vulnerabilities and prior hotfixes.
