Description

N-able has released a security update addressing CVE-2026-86218, a critical pre-authentication Remote Code Execution (RCE) vulnerability in its N-central remote monitoring and management platform. The flaw can allow an unauthenticated remote attacker to execute code on an affected N-central server. The vulnerability carries a CVSS v4.0 score of 10.0 (Critical) and requires no user interaction or prior authentication. CVE-2026-86218 affects N-central versions earlier than 2026.3.1.14. The vulnerability is classified as CWE-96 (Improper Neutralization of Directives in Statically Saved Code). Its pre-authentication nature means an attacker does not need valid credentials before attempting exploitation. The CVSS vector indicates network-based exploitation with low complexity, no privileges, and no user interaction, with high potential impact to confidentiality, integrity, and availability. N-able has not publicly disclosed detailed exploitation mechanics or confirmed exploitation in the wild. Because N-central provides centralized management capabilities for endpoints and customer environments, successful compromise of an exposed server could provide attackers with a significant foothold into managed infrastructure.