Four hotfixes in five weeks is the kind of cadence you expect from a buggy mobile game, not the remote monitoring software that IT teams trust to babysit their entire client fleet. Yet here we are, hotfix number four, and this one's a maximum-severity doozy.
A Perfect 10, and Not the Good Kind
N-able disclosed CVE-2026-86218 on September 6 — a pre-authentication remote code execution flaw in N-central, its remote monitoring and management (RMM) platform, carrying a maximum CVSS score of 10.0. The bug affects on-premises N-central deployments running versions before 2026.3.1.14, and lets an unauthenticated attacker execute code on the server outright — no login required.
N-able shipped N-central 2026.3 Hotfix 4 to close the hole and says hosted (NCOD) instances were already patched automatically. Reports on active exploitation are mixed — N-able says it's found no evidence of exploitation in production, while researchers tracking the flaw report it has been seen exploited in the wild. Either way, this marks the fifth N-able vulnerability disclosed in just a few weeks, and on-prem customers are being told, again, to patch immediately.
RMM Tools Are the Keys to the Kingdom
RMM platforms exist specifically to give one console privileged access across every endpoint a managed service provider touches — which is exactly why ransomware crews have made them a favorite target for years. A pre-auth RCE in a tool built to remotely execute commands on client machines isn't just a bad bug, it's close to a worst-case scenario for the MSPs and businesses relying on it.
The pattern that should actually worry you isn't this one CVE — it's the frequency. Five disclosures in a matter of weeks in the same product line means whoever's running your infrastructure needs a patch cadence measured in days, not a quarterly "we'll get to it" ticket buried in a backlog.
A tool built to protect your whole network is only as trustworthy as the last time someone actually updated it.
If you don't have a clear answer for how fast critical patches actually reach every system touching your website and infrastructure, our free security checklist is a solid place to start closing that gap.
Source: The Hacker News