N-able Patches Critical RCE Flaw Amid Exploitation Concerns
N-able has released its fourth hotfix in five weeks for its N-central remote monitoring and management (RMM) platform, addressing a critical vulnerability that could allow unauthenticated remote code execution. The flaw, tracked as CVE202686218, carries a maximum CVSS score of 10.0 and affects all on-premises N-central builds prior to version 2026.3.1.14, which was released as Hotfix 4 in the early hours of September 6 UTC. N-able stated that hosted N-central instances have already been patched, but urged on-premises customers to upgrade to the latest version immediately. Conflicting information has emerged regarding whether the vulnerability has been exploited in the wild. N-able's release notes and status post indicate no confirmation of exploitation in production environments. However, the company's incident notice on its uptime status page claims the flaw "has been observed being exploited in the wild," though it does not specify who observed the activity or attribute it to any particular actor. The incident notice remained open on N-able's status page as of September 7.