---
schema: 1
kind: vulnerability
title: "CVE-2026-86206 / CVE-2026-86207 / CVE-2026-86218 — N-able N-central: a third, unrelated auth-bypass/RCE chain in five weeks, the third CVE a pre-auth CVSS 10.0 zero-day N-able says is already exploited"
headline: "N-able ships a fourth emergency hotfix in a month after a fully patched N-central server was compromised again through a brand-new flaw"
summary: >
  N-able's N-central RMM platform has shipped four emergency hotfixes against three separate,
  unrelated authentication/RCE flaw sets since 1 August 2026. Huntress found on 2026-09-04 that a
  customer's already-patched N-central server was compromised again; N-able's Hotfix 3
  (CVE-2026-86206, CVE-2026-86207) followed on 2026-09-05, and a third, independent researcher then
  reported CVE-2026-86218 — a pre-auth CVSS 10.0 remote-code-execution zero-day N-able's own Active
  Incident dashboard states has been observed exploited in the wild. Hotfix 4 (build 2026.3.1.14) is
  mandatory even for servers already on Hotfix 3.
discovered_at: "2026-09-07T04:33:00Z"
updated_at: null
event_date: "2026-09-06"
run_id: 2026-09-07T0411Z-intel
priority: critical
immediate_action:
  title: "Upgrade every self-hosted N-central server to 2026.3 Hotfix 4 (build 2026.3.1.14) now"
  action: >
    N-able's own Active Incident dashboard and N-able's Jason Murphy both state CVE-2026-86218 — a
    pre-authentication remote-code-execution flaw rated CVSS 10.0 — has been observed exploited in
    the wild, even though the concurrently published Hotfix 4 release notes hedge to no confirmed
    production exploitation. Hotfix 4 supersedes Hotfix 3 and is required even for servers already
    upgraded to it; hosted (NCOD) instances are already patched by N-able. Self-hosted
    administrators must apply Hotfix 4 immediately, restrict the N-central console to a VPN or IP
    allowlist, and audit user/role tables for accounts created without authorization — the exploit
    chain grants full administrative control over user management.
tags:
  - vulnerabilities
  - actively-exploited
  - auth-bypass
  - pre-auth
  - rce
  - zero-day
  - supply-chain
  - identity
  - patch-available
regions:
  - global
  - europe
sectors:
  - technology
  - public-sector
entities:
  - "product:n-able-n-central"
techniques:
  - T1190
  - T1136.001
  - T1219
  - T1572
affected_products:
  - "N-able N-central"
cves:
  - id: CVE-2026-86206
    cvss: "6.9"
    epss: "0.00287"
    type: auth-bypass
    vector: zero-click
    auth: pre-auth
    status: [patch-available]
    affected: "< 2026.3 HF3 (2026.3.1.13)"
    fixed: "2026.3.1.13 (HF3) / 2026.4"
  - id: CVE-2026-86207
    cvss: "7.7"
    epss: "0.00296"
    type: auth-bypass
    vector: zero-click
    auth: post-auth
    status: [patch-available]
    affected: "< 2026.3 HF3 (2026.3.1.13)"
    fixed: "2026.3.1.13 (HF3)"
  - id: CVE-2026-86218
    cvss: "10.0"
    epss: "0.00411"
    type: rce
    vector: zero-click
    auth: pre-auth
    status: [exploited, patch-available]
    affected: "< 2026.3 HF4 (2026.3.1.14), including servers already on HF3"
    fixed: "2026.3.1.14 (HF4)"
sources:
  - url: "https://www.huntress.com/blog/n-able-vulnerability-exploitation"
    publisher: "Huntress"
    date: "2026-09-06"
    role: primary
  - url: "https://status.n-able.com/2026/09/06/n-central-2026-3-hotfix-4-cve-2026-86218/"
    publisher: "N-able Status (vendor)"
    date: "2026-09-06"
    role: primary
  - url: "https://status.n-able.com/2026/09/05/n-central-2026-3-hotfix-3-cve-2026-86206-and-cve-2026-86207/"
    publisher: "N-able Status (vendor)"
    date: "2026-09-05"
    role: primary
  - url: "https://radar.offseq.com/threat/cve-2026-86206-cwe-791-incomplete-filtering-of-special-elements-in-n-able-n-central-0d9778670482f7be"
    publisher: "OffSeq Threat Radar (CNA record)"
    date: "2026-09-05"
    role: corroborating
  - url: "https://radar.offseq.com/threat/cve-2026-86207-cwe-305-authentication-bypass-by-primary-weakness-in-n-able-n-central-fdc4e7f222848fbd"
    publisher: "OffSeq Threat Radar (CNA record)"
    date: "2026-09-05"
    role: corroborating
  - url: "https://radar.offseq.com/threat/cve-2026-86218-cwe-96-improper-neutralization-of-directives-in-statically-saved-code-static-code-70cdd1c30c8772ef"
    publisher: "OffSeq Threat Radar (CNA record)"
    date: "2026-09-06"
    role: corroborating
closed_sources: []
evidence:
  - quote: "Since the disclosures, a third, independent researcher alerted us to a new vulnerability that has been exploited in the wild that is unrelated to the previously disclosed CVEs."
    publisher: "Jason Murphy, N-able — via Huntress"
  - quote: "this one is a Zero day."
    publisher: "Jason Murphy, N-able — via Huntress"
  - quote: "At this time, we have no confirmations that this vulnerability has been exploited in production environments, but unpatched systems remain at risk."
    publisher: "N-able Status (vendor)"
  - quote: "This activity represents a net new exploit chain that potentially leverages one or both of two newly designated vulnerabilities (CVE-2026-86206 and CVE-2026-86207), completely distinct from the flaws addressed by N-able's August hotfixes (CVE-2026-18556 and CVE-2026-18577)."
    publisher: "Huntress"
verification: multi-source
sourcing_note: >
  N-able's own statements on CVE-2026-86218's exploitation status conflict: the Active Incident
  dashboard and N-able's Jason Murphy both say it has been observed exploited in the wild, while the
  concurrently published Hotfix 4 release notes state no confirmed production exploitation. Both
  are carried; the dashboard and Murphy's on-record statement are weighted as the vendor's
  operative position given they are more specific and postdate the release notes' boilerplate
  hedge. CVE-2026-86206's CVSS (6.9, medium) comes from OffSeq Threat Radar's CNA-sourced record
  (Assigner: N-able) rather than from N-able's own hotfix-announcement blog post, which names the
  flaw's fix but not its score. N-able's own HF3 blog post describes both CVE-2026-86206 and
  CVE-2026-86207 jointly as "high-CVSS-rated"; the per-CVE CNA record scores only CVE-2026-86207
  as High (7.7) and CVE-2026-86206 as Medium (6.9) — this entry follows the per-CVE score over the
  vendor blog's joint characterization. The CNA record's own CVSS v4.0 vector for CVE-2026-86207
  also encodes AT:P/PR:L (attack conditions present, low privileges required) rather than the
  zero-privilege profile CVE-2026-86206 and CVE-2026-86218 both genuinely carry (AT:N/PR:N); this
  entry follows that vector and classifies CVE-2026-86207 as post-auth accordingly, distinct from
  its two pre-auth sibling CVEs. Credibility is set to 2 rather than 1: the surrounding CVE
  and hotfix facts are solidly multi-source corroborated, but N-able's own communications are
  internally inconsistent on the entry's single most safety-critical fact (CVE-2026-86218's
  exploitation status), which falls short of the independent confirmation credibility 1 requires.
confidence: high
references:
  - "2026-08-03/cve-2026-18577-n-able-n-central-auth-bypass-exploited"
deep_dive: true
deep_dive_category: identity-infra
org_triage: null
classification:
  reliability: B
  credibility: 2
watchlist_hit: false
actions:
  - "Upgrade every self-hosted N-central server to 2026.3 Hotfix 4 (build 2026.3.1.14) now, even if already on Hotfix 3 — HF3 does not close CVE-2026-86218 — and restrict the console to a VPN or IP allowlist."
  - "Audit N-central user/role tables for accounts created without authorization, watching in particular for email addresses appended with an unexpected string such as \".invalid\"."
updates: []
migrated_from: null
---

N-able's N-central — the remote-monitoring-and-management (RMM) platform MSPs use to centrally patch, monitor and remotely access their customers' servers and endpoints — has now shipped four emergency hotfixes in five weeks against three separate, mechanically unrelated flaw sets. The first, disclosed 1–2 August 2026 (CVE-2026-18556 / CVE-2026-18577), remains the one confirmed to have been exploited by the Storm-1175 ransomware actor with its StormEncryptor payload ([Huntress, 2026-08-03](https://www.huntress.com/blog/n-able-vulnerability-exploitation)). This entry covers the second and third flaw sets, which N-able itself describes as unrelated to the August chain and to each other.

Huntress's investigation of the second chain began on 4 September 2026, after a customer's fully patched N-central production server was compromised again ([Huntress, 2026-09-06](https://www.huntress.com/blog/n-able-vulnerability-exploitation)). Huntress reproduced and validated a working proof-of-concept authentication bypass against N-central 2026.3.1.10 and shared it with N-able, which shipped Hotfix 3 (build 2026.3.1.13, 2026-09-05) fixing two newly designated flaws ([N-able Status, 2026-09-05](https://status.n-able.com/2026/09/05/n-central-2026-3-hotfix-3-cve-2026-86206-and-cve-2026-86207/)): CVE-2026-86206, an access-control gap in N-central's internal API filter granting unauthorized access to internal-only APIs ([OffSeq Threat Radar, 2026-09-05](https://radar.offseq.com/threat/cve-2026-86206-cwe-791-incomplete-filtering-of-special-elements-in-n-able-n-central-0d9778670482f7be)), and CVE-2026-86207 (CVSS 7.7), an authentication bypass by primary weakness reaching the same internal APIs ([OffSeq Threat Radar, 2026-09-05](https://radar.offseq.com/threat/cve-2026-86207-cwe-305-authentication-bypass-by-primary-weakness-in-n-able-n-central-fdc4e7f222848fbd)). Huntress states this "net new exploit chain… potentially leverages one or both" of the two CVEs, but because logs on the compromised appliance had already rotated by the time of investigation, it cannot confirm which specific flaw the attacker used, nor rule out a third path.

Hours after Hotfix 3 shipped, in the early morning of 6 September 2026, a third and independent researcher alerted N-able to a wholly separate zero-day: CVE-2026-86218, a pre-authentication remote-code-execution flaw (CWE-96, static code injection) rated CVSS 10.0 — the maximum possible score ([OffSeq Threat Radar, 2026-09-06](https://radar.offseq.com/threat/cve-2026-86218-cwe-96-improper-neutralization-of-directives-in-statically-saved-code-static-code-70cdd1c30c8772ef)). Huntress reports that both N-able's own Active Incident dashboard and N-able's Jason Murphy convey that this flaw has been exploited in the wild ([Huntress, 2026-09-06](https://www.huntress.com/blog/n-able-vulnerability-exploitation)) — Murphy's own quoted words state "Since the disclosures, a third, independent researcher alerted us to a new vulnerability that has been exploited in the wild"; Murphy separately confirmed on record that "this one is a Zero day." N-able's concurrently published Hotfix 4 release notes carry a narrower, conflicting statement — "we have no confirmations that this vulnerability has been exploited in production environments, but unpatched systems remain at risk" ([N-able Status, 2026-09-06](https://status.n-able.com/2026/09/06/n-central-2026-3-hotfix-4-cve-2026-86218/)) — leaving the vendor's own account internally inconsistent on confirmed exploitation while agreeing the flaw is a live zero-day. Hotfix 4 (build 2026.3.1.14) supersedes Hotfix 3 and is mandatory even for servers already running it; N-able-hosted (NCOD) instances were already remediated automatically.

Across both the August and September chains, successful exploitation grants an attacker full administrative control over N-central's user and role management — the same privilege level normally reserved for trusted NOC and engineering staff ([Huntress, 2026-09-06](https://www.huntress.com/blog/n-able-vulnerability-exploitation)). From there, an attacker can create rogue administrator accounts, push arbitrary scripts and jobs to every managed endpoint, and pivot into managed customer networks via N-central's built-in Take Control remote-access feature or by registering a persistent tunnel service ([Huntress, 2026-09-06](https://www.huntress.com/blog/n-able-vulnerability-exploitation)). Because N-central sits between an MSP and every customer network it manages, a single compromised instance is a force multiplier reaching every downstream client — a class of exposure directly relevant to any Swiss cantonal or communal administration that outsources IT operations to an MSP running this platform.

Huntress's detection guidance differs from the August incident: rather than the Take Control feature, this activity targets the underlying API and appliance logs directly. Defenders should review N-central's `envoy_proxy_HTTPS.log` and `syslog ncentraldms` for URL-encoded internal-API-route access anomalies, and audit newly created user accounts for unusual naming conventions — Huntress specifically flags email addresses suffixed with `.invalid` or similar string manipulations designed to pass casual inspection ([Huntress, 2026-09-06](https://www.huntress.com/blog/n-able-vulnerability-exploitation)). Reconnaissance for the September chain also probed the `remoteControlAction.do?method=getPierDetails` endpoint with specific appliance IDs to map the environment before exploitation. No source cited in this entry describes a public proof-of-concept for any of the three CVEs; Huntress's own reproduction remained private and was shared directly with N-able.

**Defender takeaway:** treat every self-hosted N-central instance as a high-value target regardless of prior patch level — a fully patched server was compromised again through a completely distinct flaw class within a month of the last emergency fix. Patch to Hotfix 4 now, restrict console exposure to a VPN or allowlist, enforce MFA on every N-central account, and audit for anomalous account creation and job/script pushes rather than relying on any single indicator.

**Triage:** legitimate N-central administration routinely creates new users and pushes jobs across the managed fleet, so neither activity alone is a signal. For the September chain this entry covers, the discriminator Huntress's own investigation supports is a newly created or role-elevated account whose creation coincides with anomalous internal-API access or unusual entries in the appliance's own logs. Huntress's discriminator for the separate August chain — a remote-control session from a support-style account (e.g. the default "MSP Support" identity) that targets a domain controller or other high-value host outside an expected support ticket or maintenance window — remains a valid signal for that earlier flaw set but is not the pattern Huntress observed for September's API/log-based activity.
