Managed IT software provider N-able has released a new hotfix addressing a critical remote code execution (RCE) vulnerability in its N-central platform. The flaw, identified as CVE-2026-86218, received a maximum severity rating of 10 (CVSS) and could allow unauthenticated attackers to execute code on the N-central server, according to a recent report by Infosecurity Magazine.The vulnerability affects N-central versions prior to 2026.3.1.14. N-able has not disclosed the specific component or exploitation method but stated there is no evidence of the vulnerability being exploited in the wild. The patch is included in N-central 2026.3 Hotfix 4. This is the latest in a series of vulnerabilities affecting N-able products. Previously, CVE-2026-18556 and CVE-2026-18577, both high-severity authentication bypasses that were exploited earlier in 2026, were patched in hotfixes HF1 and HF2. Additionally, CVE-2026-86207 and CVE-2026-86206, high-severity authentication bypasses and access-control filter bypasses respectively, were addressed in HF3. These vulnerabilities highlight ongoing security challenges for managed IT service providers and their clients, emphasizing the need for prompt patching and robust security practices.Source: Infosecurity Magazine