N-able N-central Pre-Auth RCE Highlights RMM Concentration Risk
A static code injection vulnerability in N-able N-central allows pre-authentication remote code execution. CVSS 4.0 score is 10.0; versions below 2026.3.1.14 are affected, with Hotfix 4 as the fix. CISA added the CVE to its exploited catalog on September 8, 2026.
- CVSS 4.0 score 10.0: network access, no privileges or user interaction
- N-central below 2026.3.1.14 vulnerable, including Hotfix 3 installs
- Fix is N-central 2026.3 Hotfix 4 (2026.3.1.14)
- CISA added CVE to KEV September 8, federal deadline September 11
Read next
Security