
N-able Hotfix 4 Fixes Unauthenticated N-central RCE Flaw
N-able patches CVE-2026-86218, a 10.0-severity unauthenticated remote code execution flaw affecting all N-central builds before 2026.3.1.14, with exploitation r…
N-able has released its fourth hotfix in five weeks for the N-central remote monitoring and management (RMM) platform to fix an N-central remote code execution (RCE) flaw tracked as CVE-2026-86218. Remote code execution means an attacker can run their own commands on the server, and this one is pre-authentication, so no valid login or account is needed. N-able, which is the CVE Numbering Authority for this record, assigned it a Common Vulnerability Scoring System (CVSS) 4.0 score of 10.0, the highest possible severity, and classified it as static code injection (CWE-96). The flaw affects every on-premises (self-hosted) N-central build before 2026.3.1.14, the version shipped as 2026.3 Hotfix 4 in the early hours of September 6 UTC. That includes servers already updated to Hotfix 3 (2026.3.1.13), which N-able had released a little over eight hours earlier for two unrelated flaws. N-able said hosted N-central instances (known as NCOD) have already been patched, but on-premises customers are told to upgrade to 2026.3.1.14 immediately. The release notes list direct upgrade paths from 2025.4, 2026.1, 2026.2, 2026.3, and the 2026.3.1 hotfixes, and say agents do not need to be upgraded to be protected from this CVE.
N-able's own communications disagree on whether the flaw has already been exploited. The Hotfix 4 release notes and a status post say a third party responsibly disclosed the vulnerability through the company's security disclosure program, and that N-able has 'no confirmations that this vulnerability has been exploited in production environments.' The same release notes on the documentation site also describe it as a 'critical zero-day vulnerability,' a term the company does not define. A zero-day is a flaw that becomes known or exploited before a vendor patch is available. However, the incident notice on N-able's uptime status page says a third, independent security researcher alerted the company to a new vulnerability unrelated to the previously disclosed CVEs, and that, unlike those, the newly identified flaw 'has been observed being exploited in the wild.' The notice does not say who observed the exploitation, where, or when, and N-able has not attributed the activity to any actor. As of September 7, the incident remained open on N-able's status page, as mirrored by the status-page aggregator IsDown. The Hacker News has reached out to N-able for clarification on which statement is current and what evidence of exploitation the company holds.
The release notes, status post, and incident notice contain no indicators of compromise (IoCs), which are digital clues that a system may have been breached, no interim mitigation, and no detection guidance beyond a recommendation to audit N-central user accounts for unexpected users. Huntress, which has been tracking attacks on N-central since August, has advised administrators to restrict inbound access to the console with IP allowlisting or a VPN and, where a server is still reachable from the internet, to consider taking it offline until the hotfix is applied. Huntress said it cannot settle the exploitation question from its own data. The company began investigating on September 4 after a customer's fully patched N-central production environment was compromised. It reproduced a proof-of-concept (PoC) exploit chain, a demonstration that the attack path works, against build 2026.3.1.10 that may use one or both of the two flaws later fixed in Hotfix 3, but the appliance's logs had already rotated, leaving it unable to say whether this new CVE was the vulnerability exploited in that intrusion. In response to questions from The Hacker News, Ben Bernstein, cybersecurity advisor at Huntress, said the 'actively exploited' description in its post is based entirely on N-able's statements, namely the incident notice and a post on the MSPGeek Discord in which N-able's Jason Murphy relayed that notice at 12:25 a.m. Eastern on September 6. Huntress has not reproduced CVE-2026-86218, Bernstein said, and has not observed new exploitation compromises definitively attributable to this CVE in its telemetry since its September 6 update. Because the flaw is pre-authentication remote code execution, Bernstein said, an internet-exposed console is the primary attack vector, which is why Huntress recommends restricting inbound network access to the console.
This hotfix is the fourth N-able has issued for the 2026.3 line since August 2 and covers the third distinct set of vulnerabilities. Hotfix 1 (2026.3.1.7), released August 2, fixed CVE-2026-18577, an incomplete fix for CVE-2026-18556 that still allowed authentication bypass and account takeover, and was exploited in the wild. Hotfix 2 (2026.3.1.10), released August 6, added additional hardening for a related attack path. Hotfix 3 (2026.3.1.13), released September 5, fixed CVE-2026-86206, unauthorized access to internal APIs through the access control filter, and CVE-2026-86207, an authentication bypass in internal-only APIs. N-able described those two flaws as high-CVSS-rated vulnerabilities that could allow an unauthorized party to bypass authentication controls and gain full access to the platform. Its own CVE records score CVE-2026-86207 at 7.7 (High) and CVE-2026-86206 at 6.9 (Medium). The company said it had no confirmation that either had been exploited in production environments.
The August hotfixes followed an intrusion N-able said it detected on July 31. Attackers used an authentication bypass to obtain administrative access to N-central servers, then used the platform's Take Control feature to reach managed endpoints and register Cloudflare tunnel services on those devices. A Cloudflare tunnel creates an encrypted connection from a device to the internet, and the attackers used it to maintain access after the route through N-central was cut off. N-able said a limited number of customers were affected, its first fix proved incomplete, and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added both CVEs to its Known Exploited Vulnerabilities catalog. On August 10, the company said a full root-cause analysis was coming. This is the second summer in a row that N-central has drawn in-the-wild attacks: in August 2025, two other flaws in the product, CVE-2025-8875 and CVE-2025-8876, were added to CISA's catalog the same day N-able released fixes for them.
For on-premises N-central customers, the immediate action is clear: upgrade to 2026.3.1.14 as soon as possible. Because there are no published indicators of compromise, administrators should also audit N-central user accounts for unexpected users, as N-able recommends. Restricting access to the console with an allowlist or a VPN reduces the attack surface, and taking an internet-exposed server offline until patching is complete is a prudent option. N-central customers who want independent help reviewing their exposure and patching process can look to AEU-I, which provides security-first IT and infrastructure consultin
How to Protect Yourself
- If your business uses N-central, ask your IT provider or administrator to confirm the software has been updated to version 2026.3.1.14 or newer.
- Make sure the N-central web console is not reachable directly from the public internet; use a VPN (a private, encrypted connection) or an allowlist of approved internet addresses.
- Review the list of user accounts in your N-central console and remove any accounts you do not recognize.
- Sign up for official N-able security notices and apply future hotfixes as soon as they are released.
- If you are a customer of a managed service provider, ask them what steps they have taken to patch and restrict console access.
Vulnerabilities & Fixes
- CVE-2025-8875 Older N-central flaw added to CISA's Known Exploited Vulnerabilities catalog in August 2025. View the fix & details →
- CVE-2025-8876 Older N-central flaw added to CISA's Known Exploited Vulnerabilities catalog in August 2025. View the fix & details →
- CVE-2026-18556 Authentication bypass in N-central, addressed by Hotfix 1 but incompletely fixed. View the fix & details →
- CVE-2026-18577 Incomplete fix for authentication bypass and account takeover in N-central, fixed in Hotfix 1 and exploited in the wild. View the fix & details →
- CVE-2026-86206 Unauthorized access to internal APIs through the access control filter, fixed in Hotfix 3. View the fix & details →
- CVE-2026-86207 Authentication bypass in internal-only APIs, fixed in Hotfix 3. View the fix & details →
- CVE-2026-86218 Pre-authentication remote code execution in N-central, fixed in 2026.3.1.14 (Hotfix 4). View the fix & details →
Terms Explained
- RMM (Remote Monitoring and Management) Software used by IT providers to monitor and manage computers and servers remotely.
- Remote code execution (RCE) A security weakness that lets an attacker run their own commands on a system without permission.
- Pre-authentication An attack that works before a user logs in, so no password or account is needed.
- CVSS (Common Vulnerability Scoring System) A standard score from 0 to 10 that measures how severe a security flaw is.
- CVE (Common Vulnerabilities and Exposures) A public ID number given to a known security weakness.
- IP allowlisting A security setting that only lets connections from approved internet addresses reach a service.
- Indicators of compromise (IoCs) Digital clues that may show a system has been broken into.
- Proof-of-concept (PoC) A small demonstration that shows a security flaw can actually be used by an attacker.