CTIPilot
← Back to the live brief
CRITICALCVE-2026-86206 +2exploitedNATOB2vulnerabilitydeep dive · identity-infra

CVE-2026-86206 / CVE-2026-86207 / CVE-2026-86218, N-able N-central: a third, unrelated auth-bypass/RCE chain in five weeks, the third CVE a pre-auth CVSS 10.0 zero-day N-able says is already exploited

N-able ships a fourth emergency hotfix in a month after a fully patched N-central server was compromised again through a brand-new flaw

Defender actions

  • Upgrade every self-hosted N-central server to 2026.3 Hotfix 4 (build 2026.3.1.14) now, even if already on Hotfix 3 (HF3 does not close CVE-2026-86218) and restrict the console to a VPN or IP allowlist.
  • Audit N-central user/role tables for accounts created without authorization, watching in particular for email addresses appended with an unexpected string such as ".invalid".

Analysis

N-able's N-central, the remote-monitoring-and-management (RMM) platform MSPs use to centrally patch, monitor and remotely access their customers' servers and endpoints, has now shipped four emergency hotfixes in five weeks against three separate, mechanically unrelated flaw sets. The first, disclosed 1–2 August 2026 (CVE-2026-18556 / CVE-2026-18577), remains the one confirmed to have been exploited by the Storm-1175 ransomware actor with its StormEncryptor payload (Huntress, 2026-08-03). This entry covers the second and third flaw sets, which N-able itself describes as unrelated to the August chain and to each other.

Huntress's investigation of the second chain began on 4 September 2026, after a customer's fully patched N-central production server was compromised again (Huntress, 2026-09-06). Huntress reproduced and validated a working proof-of-concept authentication bypass against N-central 2026.3.1.10 and shared it with N-able, which shipped Hotfix 3 (build 2026.3.1.13, 2026-09-05) fixing two newly designated flaws (N-able Status, 2026-09-05): CVE-2026-86206, an access-control gap in N-central's internal API filter granting unauthorized access to internal-only APIs (OffSeq Threat Radar, 2026-09-05), and CVE-2026-86207 (CVSS 7.7), an authentication bypass by primary weakness reaching the same internal APIs (OffSeq Threat Radar, 2026-09-05). Huntress states this "net new exploit chain… potentially leverages one or both" of the two CVEs, but because logs on the compromised appliance had already rotated by the time of investigation, it cannot confirm which specific flaw the attacker used, nor rule out a third path.

Hours after Hotfix 3 shipped, in the early morning of 6 September 2026, a third and independent researcher alerted N-able to a wholly separate zero-day: CVE-2026-86218, a pre-authentication remote-code-execution flaw (CWE-96, static code injection) rated CVSS 10.0, the maximum possible score (OffSeq Threat Radar, 2026-09-06). Huntress reports that both N-able's own Active Incident dashboard and N-able's Jason Murphy convey that this flaw has been exploited in the wild (Huntress, 2026-09-06); Murphy's own quoted words state "Since the disclosures, a third, independent researcher alerted us to a new vulnerability that has been exploited in the wild"; Murphy separately confirmed on record that "this one is a Zero day." N-able's concurrently published Hotfix 4 release notes carry a narrower, conflicting statement; "we have no confirmations that this vulnerability has been exploited in production environments, but unpatched systems remain at risk" (N-able Status, 2026-09-06), leaving the vendor's own account internally inconsistent on confirmed exploitation while agreeing the flaw is a live zero-day. Hotfix 4 (build 2026.3.1.14) supersedes Hotfix 3 and is mandatory even for servers already running it; N-able-hosted (NCOD) instances were already remediated automatically.

Across both the August and September chains, successful exploitation grants an attacker full administrative control over N-central's user and role management, the same privilege level normally reserved for trusted NOC and engineering staff (Huntress, 2026-09-06). From there, an attacker can create rogue administrator accounts, push arbitrary scripts and jobs to every managed endpoint, and pivot into managed customer networks via N-central's built-in Take Control remote-access feature or by registering a persistent tunnel service (Huntress, 2026-09-06). Because N-central sits between an MSP and every customer network it manages, a single compromised instance is a force multiplier reaching every downstream client, a class of exposure directly relevant to any Swiss cantonal or communal administration that outsources IT operations to an MSP running this platform.

Huntress's detection guidance differs from the August incident: rather than the Take Control feature, this activity targets the underlying API and appliance logs directly. Defenders should review N-central's envoy_proxy_HTTPS.log and syslog ncentraldms for URL-encoded internal-API-route access anomalies, and audit newly created user accounts for unusual naming conventions, Huntress specifically flags email addresses suffixed with .invalid or similar string manipulations designed to pass casual inspection (Huntress, 2026-09-06). Reconnaissance for the September chain also probed the remoteControlAction.do?method=getPierDetails endpoint with specific appliance IDs to map the environment before exploitation. No source cited in this entry describes a public proof-of-concept for any of the three CVEs; Huntress's own reproduction remained private and was shared directly with N-able.

Triage: legitimate N-central administration routinely creates new users and pushes jobs across the managed fleet, so neither activity alone is a signal. For the September chain this entry covers, the discriminator Huntress's own investigation supports is a newly created or role-elevated account whose creation coincides with anomalous internal-API access or unusual entries in the appliance's own logs. Huntress's discriminator for the separate August chain, a remote-control session from a support-style account (e.g. the default "MSP Support" identity) that targets a domain controller or other high-value host outside an expected support ticket or maintenance window; remains a valid signal for that earlier flaw set but is not the pattern Huntress observed for September's API/log-based activity.

Cited evidence

Since the disclosures, a third, independent researcher alerted us to a new vulnerability that has been exploited in the wild that is unrelated to the previously disclosed CVEs.

this one is a Zero day.

Jason Murphy, N-able, via Huntress

At this time, we have no confirmations that this vulnerability has been exploited in production environments, but unpatched systems remain at risk.

N-able Status (vendor) 2026-09-06

This activity represents a net new exploit chain that potentially leverages one or both of two newly designated vulnerabilities (CVE-2026-86206 and CVE-2026-86207), completely distinct from the flaws addressed by N-able's August hotfixes (CVE-2026-18556 and CVE-2026-18577).

Huntress 2026-09-06

Sources6

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.