N-able N-central CVE-2026-86218: CVSS 10 Pre-Auth RCE Exploited, One Month After August Flaw
> TL;DR: CVE-2026-86218 (CVSS 10.0) is a static code injection in N-able N-central enabling pre-authentication remote code execution — fixed in N-central 2026.3 Hotfix 4, released September 5, 2026. N-able has told customers the flaw "has been observed being exploited in the wild," and CISA added it to the KEV catalog with a September 11 deadline. Meanwhile, Huntress is investigating a fully patched customer N-central production environment compromised on September 4 — unable to determine whether the vector is this flaw or the two chainable vulnerabilities patched the same day (CVE-2026-86206 and CVE-2026-86207), which let an unauthenticated attacker create an attacker-controlled System Administrator account.
A platform under continuous pressure
This is the second major N-central episode in a month, after August's authentication bypass (CVE-2026-18577) where attackers hijacked MSP RMM servers and deployed Cloudflare tunnels for persistence. This season's pattern is identical: a platform administering thousands of machines becomes the priority target, because one compromise opens access to everything managed downstream.
watchTowr reproduced CVE-2026-86218 and described the stakes precisely: the code execution allows changes in N-central that "can propagate across all connected systems." Compromise an MSP's server and you reach every endpoint of every client — hence ransomware gangs' longstanding interest in this product.
The detail that should alarm you: a patched server compromised
The most unsettling part is the Huntress-investigated incident: a fully patched N-central production environment compromised on September 4. Vector attribution remains uncertain (insufficient historical logging on the appliance), with three candidates — CVE-2026-86218, or the CVE-2026-86206/86207 pair (authentication bypass then rogue System Administrator account creation, found by Rapid7). Three operational consequences:
What to do
The broader lesson
Concentrated administration platforms — RMM, PAM, endpoint management consoles, and ultimately any multi-tenant SaaS back office — have become strategic assets for attackers, exactly like IdPs. Their security is not just versioning: restricted exposure, central logging, account-creation detection, downstream monitoring. If your product is that kind of console for your customers, those four requirements are part of your security promise — and belong in your audits.
Building HR, payroll, or recruiting software? CleanIssue performs security audits for HR SaaS in real-world conditions, no source code access needed. For a first read of your exposure, start with an external review of your application.
Related articles
Three adjacent analyses to keep exploring the same attack surface.
PaperCut NG/MF: Two Zero-Days Chained for Unauthenticated RCE, Incomplete Patches, and a CISA Deadline
Flaws in the PaperCut NG and MF print management software are exploited in real attacks: an authentication bypass (CVE-2026-81578) followed by unsafe dynamic class loading (CVE-2026-82078) leads to arbitrary Java code execution without an account. Two successive emergency patches, patch bypasses already identified against the latest fully patched version, and a CISA KEV entry with a September 14, 2026 deadline.
N-able N-central CVE-2026-18577: MSP servers hijacked via auth bypass, persisted with Cloudflare tunnels
An authentication bypass (CVE-2026-18577) in N-able's N-central RMM platform let attackers gain remote administrative access and reach customer endpoints. They registered Cloudflare tunnels as services for persistent, firewall-evading access. The first fix was incomplete. Fixed in build 2026.3.1.7.
GitLab CVE-2026-85706: Unauthenticated Arbitrary File Read (CVSS 10), Scanned Within Hours
A path traversal in the repository commits API (CVE-2026-85706, CVSS 10.0) lets an unauthenticated user read arbitrary files from the GitLab server — logs and configuration holding credentials and secrets — as soon as one public project exists. Active probes observed September 11; CISA KEV with a September 14 deadline. Fixes: 19.1.8, 19.2.6, 19.3.2, also covering an EE deserialization flaw (CVE-2026-87719, 9.9).
Sources
Related services
If this topic maps to a real risk in your stack, these are the most relevant CleanIssue audits.