N-able Denied Exploits Four Days Before Confirming Them
Security / news
N-able Denied Exploits Four Days Before Confirming Them
N-able said Sept. 5 it had no confirmed exploits of its N-central flaws; CISA added one to its exploited-vulnerabilities catalog Sept. 8, and N-able itself confirmed a handful of breaches the next day.
[No credentials required, network access to the server alone] An attacker who can reach an N-able N-central server can run arbitrary code without logging in, N-able said in the fourth security hotfix it has shipped for its managed service provider platform in five weeks.
N-able tracks the bug as CVE-2026-86218 and rates it a maximum 10.0 on the CVSS scale. It classifies the flaw as static code injection, meaning an attacker can inject directives into code the server saves and later executes, with no authentication and no user interaction needed. N-able patched it in N-central build 2026.3.1.14, released as Hotfix 4 on Sept. 6.
What N-able said, and when it stopped saying it
When N-able shipped the previous hotfix on Sept. 5 at 8:18 p.m. UTC, patching two lower-severity bugs, it said it had "no confirmations that the vulnerabilities have been exploited." Jason Murphy, N-able's head N-central nerd, told users on the MSPGeek Discord server that the newly disclosed CVE-2026-86218 "has been exploited in the wild," according to Huntress. CISA added the CVE to its Known Exploited Vulnerabilities catalog on Sept. 8. By Sept. 9 at 1:49 p.m. UTC, N-able's own status page said it had "observed a handful of successful exploits against N-central customers," a position it had explicitly ruled out four days earlier.
Four vulnerabilities, five weeks, one platform
| Hotfix | CVE | CVSS | Date |
|---|---|---|---|
| 1 | CVE-2026-18577 | Critical | Aug. 2 |
| 3 | CVE-2026-86206 | 6.9 | Sept. 5 |
| 3 | CVE-2026-86207 | 7.7 | Sept. 5 |
| 4 | CVE-2026-86218 | 10.0 | Sept. 6 |
CVE-2026-18577, patched Aug. 2, was itself already under attack when N-able fixed it, following an incomplete earlier patch. CVE-2026-86218 is the third distinct N-central vulnerability N-able has disclosed in six weeks.
What Huntress could not confirm
Huntress found one compromised N-central customer in its own telemetry, but said in a Sept. 6 post by Ben Bernstein and John Hammond that logs on the server had already rotated by the time it investigated, making it impossible to say which of N-able's four 2026 CVEs the intruder actually used.
Why an RMM platform is worth this much to an attacker
N-central exists to give managed service providers centralized control over client networks, so a compromised server can cascade into every endpoint it manages rather than staying contained to one victim. It is the same shape of exposure CISA flagged in September for a ConnectWise ScreenConnect flaw that let a modified client spread malware between remote sessions on its own, and it echoes a pattern this month's MikroTik RouterOS disclosure also showed: a vendor discloses several bugs at once, and only some of them turn out to be the ones CISA will confirm as actively exploited.
What operators still don't know
N-able has not said how many customers were among the "handful" of confirmed exploits, or whether any of them overlap with the breach Huntress is still investigating.
Sources
More in Security
- 01Cisco and Acronis Share a CISA Deadline, Not a Severity ScoreOne flaw needs no password and no user interaction, the other needs an attacker already logged in, and CISA gave federal agencies the same three days to fix both.
- 02Bransys ELD App Shipped With Hardcoded Login CredentialsCISA disclosed three flaws Sept. 17 in the trucking compliance app, including a hardcoded password a researcher says exposed live location and engine data from every connected truck on a subset of fleets.
- 03MikroTik Patches RouterOS Flaws Attackers Exploited FirstPoland's national CERT says attackers began exploiting the chained flaws on Sept. 2, a day before MikroTik shipped a fix, and more than 122,500 routers were still reachable a week later.
- 04Attackers Exploit a JFrog Artifactory Bug in Four DayswatchTowr says attackers began minting administrator tokens by abusing a default empty join key, CVE-2026-82329, within days of JFrog's own patch shipping.