September 19, 2026 A Perfect 10, No Password Required: The N-central Zero-Day (CVE-2026-86218) Your IT Provider Must Have Patched
Six weeks ago we wrote about a flaw in the tool your IT provider uses to run your computers. It is happening again – and this time it is worse. On September 6, 2026, N-able shipped an emergency hotfix for CVE-2026-86218, a vulnerability in its N-central platform that carries a perfect 10.0 severity score, requires no password at all, and has already been observed being exploited in the wild. For a dental practice, the important part is not the version number. It is a single question you should put to whoever manages your network this week: have you patched it, and were we ever exposed?
What happened
N-central is a remote monitoring and management (RMM) platform – the software many managed service providers (MSPs) use to keep an eye on, update, and remotely fix all of their clients’ computers from one console. CVE-2026-86218 is a pre-authentication remote code execution flaw in that platform. In plain terms: an attacker who can reach a vulnerable N-central server over the network can make it run their code without logging in and without any user doing anything. N-able rated it 10.0 on the CVSS scale – the maximum – and confirmed active exploitation. It affects on-premises N-central installations before version 2026.3.1.14, which is the fixed release. The Shadowserver Foundation counted roughly 1,500 internet-facing N-central servers, mostly across the US and Europe, when the flaw was disclosed – each one a high-value target.
Why an RMM flaw is a skeleton key into a clinic
An RMM console is not just another server. It is, by design, the one machine that can reach every device it manages – to push software, run scripts, and open remote sessions across many networks at once. That is enormously useful when a trusted technician is at the keyboard. It is catastrophic when an attacker is. Seize the console and you inherit its reach: potentially the workstations at the front desk, the imaging server in the back, and the practice-management database in between. This is the same lesson we drew from the N-central authentication-bypass flaw back in August – the difference is that the earlier bug still had to get past a login, while this one skips the login entirely. It is a worse version of the same skeleton key.
“But we don’t run N-central”
Almost no dental practice does – and that is precisely the trap. You very likely do not operate an N-central server yourself, so it is tempting to file this under “not our problem.” But the practices at risk are mostly exposed through their IT provider, not directly. If the company that manages your computers runs N-central to do it, then their console is a door into your network, and a flaw in their software becomes your exposure even though you did nothing wrong. Security people call this fourth-party risk: not your vendor, but your vendor’s tools. We have watched this pattern play out through a supplier before – it is exactly what happened when a dental billing company ended up on a ransomware leak site and the practices that used it were dragged along. The RMM version is more dangerous, because an RMM has hands-on control of your machines, not just a copy of your data.
Why this one earns the perfect 10
Not every “critical” advisory deserves the same alarm. This one does, for three compounding reasons. It is pre-authentication, so the usual last line of defence – a login the attacker has to defeat – is not even in the way. It is remote code execution, the most complete form of compromise, letting the attacker run whatever they want on the server. And it is already being exploited, which turns “patch when convenient” into “patch now.” N-able also has recent history here: earlier N-central flaws (CVE-2025-8875 and CVE-2025-8876) were exploited and later added to the US CISA Known Exploited Vulnerabilities catalog, the government’s list of bugs attackers are actively using. A platform that has been hit repeatedly, that sits at the centre of many networks, and that is reachable from the internet is exactly the kind of target that attracts sustained attention.
What to do this week
You cannot apply this patch yourself – it lives on your provider’s infrastructure. What you can do is verify, and verification is your right as the customer whose patient data is at stake. Ask your IT provider, plainly:
- Do you use N-able N-central to manage our systems? A straight yes/no. If yes, continue down the list.
- Is it on-premises, and has it been updated to 2026.3.1.14? The fix is that version or later. “We’re on it” is not an answer; a version number is.
- Was the console ever reachable from the public internet during the exposure window? A management console has no business facing the open internet. It belongs behind a firewall or VPN – the same principle we applied to hardening remote access appliances: if it does not need to be public, it should not be.
- If there was any exposure, what is your compromise-assumption plan? A mature provider will not just patch and move on; they will check for signs of intrusion, rotate credentials, and tell you what they found.
- Are our backups current, tested, and offline? If the worst happened through any vendor, clean backups you have actually restored from are what get the practice running again – which is the heart of having a real downtime and business-continuity plan rather than hoping.
Good providers will welcome these questions and answer them crisply, because they have already done the work. A provider who is evasive, or who cannot tell you what software they run in your environment, has told you something important too.
What this means for your practice
CVE-2026-86218 is a reminder that your security perimeter no longer ends at your own walls – it now includes the tools your suppliers use to reach inside them. That is not a reason for paranoia; it is a reason for a short, specific conversation with whoever holds the keys to your network. Compudent Systems manages dental practices across the GTA and Ontario with that fourth-party exposure in mind: we keep our management tooling patched and off the public internet, we design for the assumption that any vendor can have a bad day, and we make sure a practice’s backups and downtime plan would actually carry it through one. If you are not certain whether the software running your office has been patched against this flaw – or you would simply like a second set of eyes on who can reach your systems and how – contact Compudent for a security assessment. A perfect-10, no-password flaw in the wrong tool is the kind of thing you want to have already handled, not to be reading about after the fact.
Sources & further reading:
- The Hacker News – N-able N-central Pre-Auth RCE Flaw Exploited in the Wild
- Huntress – Critical N-able N-central Vulnerability and Active Exploitation
- Horizon3 – CVE-2026-86218: N-able N-central RCE
Related Reading
- When the Tool That Manages Your Network Gets Hacked: The N-able N-central Breach and What It Means for Dental Practices
- A Forged Login Walks Straight Into SharePoint: What the Actively Exploited CVE-2026-55040 Auth Bypass Means for Dental Practices
- Ransomware Gangs Are Now Through the Front Door: What the SonicWall SMA1000 VPN Attacks Mean for Dental Practices