Critical CVE-2026-86218, CVE-2026-18556, CVE-2026-18577, CVE-2026-48558 — N-able N-central has had three exploited flaws since August 2026, ending with a CVSS 10 pre-auth RCE, and SimpleHelp has a forged-token login bypass. If your IT provider uses either, here's what to check. Fixed in N-central 2026.3.1.14 and SimpleHelp 5.5.16.
Published 2026-10-08 · Last updated 2026-10-08
TL;DR: Remote monitoring and management (RMM) and remote-support tools can push software to every client computer at once, which makes them a ransomware crew's favourite target. N-central had an admin-takeover bug, then a bypass of its patch, then a CVSS 10 pre-auth RCE, all exploited. SimpleHelp accepted forged login tokens when OIDC was enabled. Upgrade to N-central 2026.3.1.14+ and SimpleHelp 5.5.16+, and if you're a client of an MSP, ask them to confirm.
| CVE-2026-86218 | N-central pre-authentication remote code execution. CVSS 4.0: 10. Fixed in 2026.3.1.14 (Hotfix 4). KEV 2026-09-08 |
|---|---|
| CVE-2026-18556 | N-central unauthenticated admin account takeover (through 2026.1). KEV 2026-08-04 |
| CVE-2026-18577 | Incomplete patch for 18556 → same takeover (through 2026.3.1). Fixed in 2026.3.1.7. KEV 2026-08-03 |
| CVE-2026-48558 | SimpleHelp OIDC login accepts unsigned tokens → full technician session, may bypass MFA. CVSS 10. KEV 2026-06-29 |
| SimpleHelp affected | 5.5.0–5.5.15 and 6.0 pre-releases before RC2, when OIDC is configured |
An RMM server can run scripts and install software on every machine it manages. Breaking into one MSP’s RMM gives an attacker every one of that MSP’s customers at once, and that’s exactly how several of the largest ransomware incidents have unfolded. Exploited bugs in these tools should be treated as emergencies.
N-able’s cloud-hosted N-central instances are patched by N-able. On-premises servers must be updated by whoever runs them.
When SimpleHelp is set up to log technicians in through an OpenID Connect identity provider (Entra ID, Okta, Google, etc.), versions up to 5.5.15 accepted the identity token without checking its signature. An attacker could forge a token claiming to be any technician and get a fully authenticated session; depending on configuration, that also skipped MFA. Servers not using OIDC login aren’t exposed to this particular bug, but should still update. SimpleHelp has had other exploited bugs in the past.
Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.