N-able has released an emergency hotfix for a maximum-severity remote code execution (RCE) flaw affecting its N-central remote monitoring and management (RMM) platform.
IT departments and managed service providers (MSPs) use the N-central platform to monitor, manage, and maintain client networks and devices from a centralized web-based console.
Tracked as CVE-2026-86218, this RCE vulnerability allows threat actors without privileges to execute malicious code on unpatched N-central instances exposed online in low-complexity attacks.
N-able addressed the flaw on Saturday by releasing N-central 2026.3 Hotfix 4 and urging customers to patch as soon as possible.
"At this time, we have no confirmations that this vulnerability has been exploited in production environments, but unpatched systems remain at risk," the company said.











