N-able Issues Fourth Emergency Hotfix for Critical RCE Vulnerability in N-central RMM Platform
N-able has released its fourth emergency hotfix in five weeks, patching a maximum-severity, pre-authentication remote code execution (RCE) flaw (CVE-2026-86218) in its N-central RMM platform. The vulnerability, with a CVSS score of 10.0, allows any attacker who can reach the server to execute code without credentials. While N-able's advisory states no confirmed exploitation, independent security researchers have confirmed a customer compromise two days before the patch was released, with approximately 1,500 internet-facing N-central servers remaining exposed.
Want more?
Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.
Open NewsSnap.ai