N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw Swati KhandelwalSep 07, 2026Vulnerability / Enterprise Security Every on-premises N-central build below 2026.3.1.14 — including servers updated to Hotfix 3 a day earlier — needs Hotfix 4. N-able's incident notice says the flaw has been exploited in the wild; its release notes say that is unconfirmed. N-able has released its fourth hotfix in five weeks for the N-central remote monitoring and management (RMM) platform, this time for a maximum-severity vulnerability that could allow remote code execution on the N-central server without authentication. The company's own communications disagree on whether the flaw has already been exploited. The vulnerability, tracked as CVE-2026-86218, carries a CVSS 4.0 score of 10.0, assigned…
CVEs: CVE-2026-86218, CVE-2026-18577, CVE-2026-18556, CVE-2026-86206, CVE-2026-86207, CVE-2025-8875, CVE-2025-8876
Original source: thehackernews.com