A maximum-severity security flaw in N-able's N-central remote monitoring platform is being actively exploited, and it does not require a password to exploit.
- What it is: CVE-2026-86218 is a maximum-severity (CVSS 10.0) vulnerability that lets an attacker run commands on an exposed N-central server without logging in.
- Who is affected: Businesses and IT providers running on-premises N-central installations, particularly any exposed to the internet.
- The risk: A successful attack hands over full control of the server, which typically manages remote access to every device it monitors.
- What to do: N-able has released Hotfix 4 (build 2026.3.1.14). Any system still on an earlier build needs the update applied immediately.
We recommend confirming with your IT provider that any N-central infrastructure in use is on the latest hotfix.
Source: Help Net Security