N-able Releases N-central Hotfix 4 for CVSS 10.0 RCE

N-able issues emergency N-central update
N-able has released 2026.3 Hotfix 4 for its N-central remote monitoring and management platform, addressing CVE-2026-86218, a maximum-severity vulnerability that can enable unauthenticated remote code execution on an N-central server. The fix is build 2026.3.1.14, released on September 6, and applies to every on-premises N-central build below that version.
The update is N-able’s fourth hotfix for the 2026.3 release line in five weeks. It supersedes Hotfix 3, build 2026.3.1.13, which the company published a little more than eight hours earlier for two unrelated vulnerabilities. Servers already updated to Hotfix 3 must therefore install Hotfix 4.
N-able, acting as the CVE Numbering Authority, assigned CVE-2026-86218 a CVSS 4.0 score of 10.0 and classified it as a static code injection weakness, CWE-96. The company said hosted N-central, or NCOD, instances have already been patched. Its release notes list direct upgrade paths from versions 2025.4, 2026.1, 2026.2, 2026.3 and the 2026.3.1 hotfix builds. N-central agents do not need to be upgraded for protection from this CVE.
Conflicting statements on active exploitation
N-able’s communications differ over whether attackers have used the flaw. The Hotfix 4 release notes and a status post say a third party responsibly disclosed the issue through the security disclosure program and state that N-able has no confirmation of exploitation in production environments.
However, an incident notice on N-able’s uptime status page says an independent researcher reported a new vulnerability unrelated to the prior CVEs and that the flaw had been observed being exploited in the wild. The notice does not identify who made that observation, where activity occurred, when it was seen, or any responsible threat actor. As of September 7, the incident remained open on the company’s status page.
The available materials contain no indicators of compromise, interim mitigation, or detailed detection guidance. N-able recommends auditing N-central user accounts for unexpected users. Huntress, which began investigating attacks involving N-central in August, has advised administrators to restrict inbound console access through IP allowlisting or a VPN. Where an N-central server remains internet-reachable, Huntress said administrators should consider taking it offline until the hotfix is installed.
A rapid sequence of N-central fixes
Hotfix 4 follows three releases since August 2. Hotfix 1, build 2026.3.1.7, addressed CVE-2026-18577, an incomplete fix for CVE-2026-18556 that still allowed authentication bypass and account takeover. Hotfix 2, build 2026.3.1.10, added hardening for a related attack path. Hotfix 3 addressed CVE-2026-86206 and CVE-2026-86207, involving access to internal APIs and an authentication bypass in internal-only APIs.
The August fixes followed an intrusion detected on July 31, when attackers used an authentication bypass to gain administrative access to N-central servers. N-able said attackers then used Take Control to access managed endpoints and registered Cloudflare tunnel services on devices to retain access. CISA added the earlier CVEs to its Known Exploited Vulnerabilities catalog.
For businesses running N-central on premises, the immediate operational priority is to identify every server below 2026.3.1.14, install Hotfix 4 without relying on Hotfix 3, reduce console exposure, and review accounts while the exploitation status remains unclear.

