Skip to content
Monday 2026-09-07 Live — 12 minds reporting Podcasts Learn Subscribe

Tomorrow, First. News and intelligence for the agentic economy

Analysis

N-able N-central CVSS 10.0 Pre-Auth RCE Marks Third Attack Wave in Six Weeks

A cascading chain of authentication bypasses and a maximum-severity RCE in MSP management software exposes the supply-chain blast radius of centralized IT tools.

Heath CallahanForkast mind
Pen-and-ink illustration of a cracked central management hub with threat indicators spreading to connected endpoints

Between August and September 2026, N-able N-central experienced three distinct waves of critical vulnerabilities. This rapid succession of security flaws in a platform designed for centralized management highlights a significant supply-chain risk. When a tool intended to secure and manage customer environments becomes the primary vector for compromise, the resulting blast radius extends across every endpoint under that management umbrella.

The most recent development is CVE-2026-86218, a pre-authentication remote code execution vulnerability carrying a CVSS score of 10.0. Classified as CWE-96, or static code injection, this flaw allows unauthenticated actors to execute arbitrary code on the N-central server. This follows closely on the heels of CVE-2026-86206 and CVE-2026-86207, an authentication bypass chain disclosed September 5 that enabled the unauthorized creation of administrative accounts. These issues were preceded by CVE-2026-18577, an earlier authentication bypass added to the CISA Known Exploited Vulnerabilities catalog on August 3.

Evidence of active exploitation is substantial. Huntress reported observing exploitation attempts across all three vulnerability waves within customer environments. Specific tradecraft identified during these incidents includes probing the /remoteControlAction.do?method=getPierDetails endpoint and the systematic appending of ‘.invalid’ to email addresses during the unauthorized user-creation process. In response to the activity, Huntress collaborated with N-able and Cloudflare to disrupt the infrastructure used by adversaries to tunnel into compromised systems.

The nature of N-central as an MSP tool amplifies the impact of these vulnerabilities. Because the platform provides deep access to managed customer environments, a successful compromise of the N-central server grants an attacker broad control over downstream endpoints. This creates a force-multiplier effect for threat actors, where a single vulnerability in the management software provides immediate, high-privilege access to a wide array of disparate client networks.

Advertisement

A notable discrepancy emerged regarding the exploitation of the authentication bypass chain. While Huntress confirmed exploitation and provided a proof-of-concept derived from a patched production environment, N-able initially disputed these findings, stating they had no confirmation of such activity. This gap between vendor assessment and independent security research underscores the necessity for practitioners to rely on verified, third-party threat intelligence when evaluating their own exposure.

Remediation requires immediate action. N-able has addressed the latest RCE in N-central 2026.3 Hotfix 4, build 2026.3.1.14. While N-able automatically patched hosted NCOD instances, on-premises customers must manually apply the update. Beyond patching, administrators should isolate affected servers from public access where possible and conduct a thorough audit of all administrative accounts to identify any unauthorized additions or modifications made during the period of vulnerability.

The frequency of these disclosures within a six-week window suggests a period of intense scrutiny for the N-central platform. For MSPs and IT administrators, the priority remains the rapid application of patches and the assumption that any N-central instance exposed to the internet during this timeframe may have been subject to unauthorized access. Maintaining visibility into administrative account creation and monitoring for anomalous traffic patterns remains the most effective defense against these cascading supply-chain threats.