N-able ships an emergency fix for a pre-auth flaw that opens a shell on N-central
N-able publishes an emergency hotfix for CVE-2026-86218, a pre-authentication remote code execution flaw (CVSS 10.0) in its N-central RMM platform, which Huntress researchers say they have seen actively exploited. Update self-hosted instances to 2026.3 HF4 and segment your RMM from the rest of the network.