Critical RCE Vulnerability in N-able N-central Exploited in the Wild (CVE-2026-86218)
A critical remote code execution (RCE) vulnerability, CVE-2026-86218, has been patched in N-able's N-central remote monitoring and management (RMM) solution. The vulnerability, rated as critical, allows for pre-authenticated RCE on the N-central server and has been actively exploited in the wild. N-able released an emergency hotfix on September 5, 2026, to address the flaw. Organizations using N-central should immediately apply the hotfix to prevent exploitation.