Updated: N-able Releases Hotfix 4 for Critical N-central Flaw as Incident Notice Reports Exploitation

N-able released Hotfix 4 for CVE-2026-86218 in on-premises N-central installations. The vendor’s incident notice now reports exploitation in the wild, but its release notes remain contradictory.

Updated: N-able’s primary incident notice has been added. According to it, CVE-2026-86218 was observed being exploited in the wild, although the vendor’s release notes still do not confirm this.

N-able released N-central Hotfix 4 for the critical CVE-2026-86218 vulnerability in the on-premises N-central platform. It is a pre-authentication flaw enabling remote code execution, meaning an attack without prior login. N-able’s new incident notice also states that a separate new vulnerability was observed being exploited in the wild.

The fix is available as N-central 2026.3 Hotfix 4, build 2026.3.1.14. It replaces the previous Hotfix 3, and organizations that already deployed build 2026.3.1.13 must also update. According to the vendor, hosted NCOD instances have already been fixed; the customer update applies to on-premises deployments.

N-central Hotfix 4 for On-Premises Servers

CVE-2026-86218 affects the N-central RMM console used for remote management of IT environments. Compromise of such a server could allow an attacker to affect the management of a large number of endpoints. N-able therefore released Hotfix 4 as the current fix for on-premises servers.

On-premises installations running versions before build 2026.3.1.14 are affected. An independent NHS England security alert also points to the need to deploy this fix version. Administrators should verify the current build of their N-central server and move to 2026.3.1.14 if they are not already using it.

Contradictory Statements on Exploitation

N-able’s communications still contain a significant contradiction. The vendor’s active incident notice explicitly says that a separate new vulnerability was observed being exploited in the wild. The Hotfix 4 release notes, by contrast, still state that N-able has no confirmation that this vulnerability was exploited in production environments.

It has not been publicly clarified why these two statements differ or which represents the company’s current position on CVE-2026-86218. The attackers’ identity, the number of affected organizations, and the complete attack chain have also not been confirmed.

In addition, Huntress was unable to confirm from available historical logs that the compromise of one customer on September 4, 2026, was caused specifically by CVE-2026-86218. It also allows for a possible connection to CVE-2026-86206 or CVE-2026-86207.

What Administrators Should Do

  • Verify the version of the on-premises N-central server.
  • Deploy build 2026.3.1.14, or N-central Hotfix 4, even if Hotfix 3 was previously installed.
  • According to N-able, no customer update is required for hosted NCOD.

Further information may concern the alignment of N-able’s statements on active exploitation, technical details, indicators of compromise, and the scope of affected on-premises deployments.

Sources

Verified and updated: 09/08/2026 06:22

Sharing