
N-able Ships Fourth N-central Hotfix in Five Weeks for CVE-2026-86218 RCE Despite Internal Contradiction on Exploitation
N-able's fourth rapid hotfix for N-central exposes ongoing code-quality problems and contradictory internal reporting on active exploitation of a critical unauthenticated RCE. The episode continues a five-week pattern of emergency patches that leaves MSP customers exposed and underscores the operational risk of relying on frequently updated RMM infrastructure without strict network segmentation.
The vulnerability affects the 2026.3 line and all prior supported versions. Hotfix 3 had shipped only eight hours earlier for unrelated issues, marking the fourth emergency patch since August 2. N-able states hosted instances are already updated and that agents require no changes. No IOCs, detection rules, or interim controls were published beyond a generic user-account audit recommendation.
Huntress: At least two additional confirmed N-central compromises via unpatched RMM flaws will appear in public reporting before October 15.
Sources (3)
- [1]Primary Source(https://thehackernews.com/2026/09/n-able-issues-fourth-n-central-hotfix.html)
- [2]Supporting Source(https://status.n-able.com/incidents)
- [3]Supporting Source(https://www.huntress.com/blog/n-central-investigation)