logo

N-able Releases Hotfix for Critical Remote Code Execution Vulnerability

ID: 67e2f8e1-7cc6-5752-9e58-a8aab20aba9f

STIX ID: report--67e2f8e1-7cc6-5752-9e58-a8aab20aba9f

Feed Name: Infosecurity Magazine (News)

Threat Score
75/100

Date Published: 2026-09-07

Date Updated: 2026-09-11

...
...

N-able released a hotfix (N-central 2026.3 Hotfix 4, build 2026.3.1.14) to address CVE-2026-86218, a critical pre-authentication RCE in N-central with a CVSS score of 10; the vendor reports no evidence of in-the-wild exploitation for this issue. The report also notes multiple recent high-severity vulnerabilities in N-able products—two authentication bypasses (CVE-2026-18556, CVE-2026-18577) were previously observed exploited and added to CISA’s KEV catalog, and other access-control/authentication issues were patched in earlier hotfixes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.