N-able rushes hotfix for critical N-central RCE flaw amid signs of active abuse
N-able released N-central 2026.3 Hotfix 4 on Saturday to fix CVE-2026-86218, a maximum-severity remote code execution bug that lets unauthenticated attackers run code on unpatched, internet-exposed servers. Shadowserver counts nearly 1,500 exposed N-central instances, mostly in the US and Europe, while security firm Huntress suspects the flaw, along with two related authentication-bypass bugs, may already have been exploited as a zero-day in at least one customer breach.