N-able N-central pre-auth RCE reportedly exploited in the wild
N-able issued a September 5 hotfix for critical CVE-2026-86218 affecting its N-central RMM platform, widely used by MSPs and enterprise customers. Exploitation reporting and customer messaging conflict on the exact vulnerability involved, so defenders should validate patch status, audit RMM accounts and activity, preserve logs, and investigate for persistence or lateral movement.
Sources (2)
Updated Sep 8, 2026