Emergency hotfix issued for critical N-central remote code execution bug

N-able has released an emergency hotfix for a critical remote code execution vulnerability (CVE-2026-86218) in its N-central RMM platform. The flaw allows unauthenticated attackers to execute code on exposed instances. While no confirmed exploitation, security researchers suspect it may be targeted, and nearly 1,500 servers are exposed online.
The emergency patch, N-central 2026.3 HF4, addresses the flaw. Shadowserver tracks roughly 1,500 internet-exposed N-central servers, predominantly located in the United States and Europe, leaving a substantial attack surface.
Huntress researchers flagged the vulnerability as a potential zero-day, alongside two authentication bypass flaws patched simultaneously. They noted that log rotation on a compromised customer server prevented confirming which specific vulnerability was exploited. This follows a pattern from a year ago, when attackers actively exploited two separate N-central flaws (CVE-2025-8875 and CVE-2025-8876).
The exposure of N-central servers could enable a severe supply-chain attack, as managed service providers rely on this platform to oversee numerous client networks. If attackers successfully exploit this flaw, they may gain centralized control over downstream businesses, potentially leading to widespread ransomware deployments or data theft across multiple organizations. Historical patch adoption rates suggest many environments could remain vulnerable for an extended period, amplifying the potential impact on critical infrastructure and small businesses.