Desert Forge IT — Arizona IT · Field-tested tools & guidesFree consult →

MSP Tools Under Attack: N-able N-central Pre-Auth RCE (CVE-2026-86218) and SimpleHelp Auth Bypass (CVE-2026-48558)

Critical CVE-2026-86218, CVE-2026-18556, CVE-2026-18577, CVE-2026-48558 — N-able N-central has had three exploited flaws since August 2026, ending with a CVSS 10 pre-auth RCE, and SimpleHelp has a forged-token login bypass. If your IT provider uses either, here's what to check. Fixed in N-central 2026.3.1.14 and SimpleHelp 5.5.16.

Published 2026-10-08 · Last updated 2026-10-08

TL;DR: Remote monitoring and management (RMM) and remote-support tools can push software to every client computer at once, which makes them a ransomware crew's favourite target. N-central had an admin-takeover bug, then a bypass of its patch, then a CVSS 10 pre-auth RCE, all exploited. SimpleHelp accepted forged login tokens when OIDC was enabled. Upgrade to N-central 2026.3.1.14+ and SimpleHelp 5.5.16+, and if you're a client of an MSP, ask them to confirm.

CVE-2026-86218N-central pre-authentication remote code execution. CVSS 4.0: 10. Fixed in 2026.3.1.14 (Hotfix 4). KEV 2026-09-08
CVE-2026-18556N-central unauthenticated admin account takeover (through 2026.1). KEV 2026-08-04
CVE-2026-18577Incomplete patch for 18556 → same takeover (through 2026.3.1). Fixed in 2026.3.1.7. KEV 2026-08-03
CVE-2026-48558SimpleHelp OIDC login accepts unsigned tokens → full technician session, may bypass MFA. CVSS 10. KEV 2026-06-29
SimpleHelp affected5.5.0–5.5.15 and 6.0 pre-releases before RC2, when OIDC is configured

Why these matter more than most

An RMM server can run scripts and install software on every machine it manages. Breaking into one MSP’s RMM gives an attacker every one of that MSP’s customers at once, and that’s exactly how several of the largest ransomware incidents have unfolded. Exploited bugs in these tools should be treated as emergencies.

N-able N-central: three exploited bugs in five weeks

  1. CVE-2026-18556 (Aug 1): an alternate-path authentication bypass allowed unauthenticated takeover of an administrative account in N-central through 2026.1.
  2. CVE-2026-18577 (Aug 2): the fix for 18556 was incomplete; the same takeover worked on versions through 2026.3.1. N-able shipped 2026.3 Hotfix 1 (2026.3.1.7).
  3. CVE-2026-86218 (Sep 6): a pre-authentication remote code execution, CVSS 10. Fixed in 2026.3 Hotfix 4, version 2026.3.1.14.

N-able’s cloud-hosted N-central instances are patched by N-able. On-premises servers must be updated by whoever runs them.

SimpleHelp: forged login tokens

When SimpleHelp is set up to log technicians in through an OpenID Connect identity provider (Entra ID, Okta, Google, etc.), versions up to 5.5.15 accepted the identity token without checking its signature. An attacker could forge a token claiming to be any technician and get a fully authenticated session; depending on configuration, that also skipped MFA. Servers not using OIDC login aren’t exposed to this particular bug, but should still update. SimpleHelp has had other exploited bugs in the past.

Am I affected?

  • N-central: the version is shown in the UI footer and under Administration → About. Anything below 2026.3.1.14 needs updating.
  • SimpleHelp: the version is on the server’s web page and in the Technician app’s About box. Below 5.5.16 (or a 6.0 build before RC2) with OIDC enabled is vulnerable.
  • Using an MSP? Ask them directly: which RMM/remote tools do you use on our machines, are they cloud or self-hosted, and are they on the fixed versions? A good MSP will have an answer the same day.

How to patch

  • N-central on-prem: install 2026.3 Hotfix 4 (2026.3.1.14) or later from the N-able customer portal. Follow N-able’s status-page guidance for each hotfix.
  • SimpleHelp: upgrade the server to 5.5.16 or later; clients update from the server automatically.
  • Restrict the admin/technician web interfaces to known IPs or a VPN wherever the product allows it.

Check for compromise

  • Review N-central and SimpleHelp admin/technician accounts for any you didn’t create, and the audit logs for logins from unfamiliar IPs or at odd hours.
  • Look for scripts, automation policies or software deployments nobody on your team scheduled. That’s how ransomware gets pushed.
  • On managed endpoints, look for new remote-access tools (AnyDesk, ScreenConnect, Atera, etc.) you didn’t install.
  • Horizon3.ai published indicators of compromise for the SimpleHelp bypass (linked below).

Sources

← Back to Knowledge Base

Want this handled for you?

Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.

Get a free security check →  ·  More security advisories