Threat Intelligence

N-able Rushes Out Fourth N-central Hotfix in Five Weeks for Critical Unauthenticated RCE Bug

The Hacker News · 7 Sept 2026
Key Takeaway If your business or IT provider uses N-able's N-central platform, apply Hotfix 4 immediately and restrict remote access to the console until you confirm the update is installed.

N-able has released another urgent hotfix for its N-central remote monitoring and management platform, this time addressing a maximum-severity vulnerability (CVE-2026-86218, CVSS 10.0) that could allow attackers to run code on an N-central server without needing to log in. The flaw affects every on-premises build before version 2026.3.1.14, including servers that were updated to Hotfix 3 just a day earlier for unrelated issues. Hosted N-central customers have already been patched by N-able, but on-premises users must upgrade immediately.

Notably, N-able's own communications disagree on whether this vulnerability has already been used in attacks. Its incident notice suggests exploitation may have occurred, while its release notes state there are no confirmed cases of exploitation in production environments, despite also describing the bug as a 'critical zero-day vulnerability'. Security firm Huntress, which has tracked attacks on N-central since August, is advising administrators to restrict access to the console using IP allowlisting or a VPN, and to consider taking internet-facing servers offline until the patch is applied.

N-able's guidance offers no indicators of compromise or detection advice beyond checking for unexpected user accounts. This is the fourth hotfix for N-central in five weeks, underscoring ongoing stability and security concerns with the platform.

N-able N-central RMM security vulnerability patch management

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.