Updated: N-able Releases Hotfix 4 for Critical N-central Flaw as Incident Notice Reports Exploitation
N-able released Hotfix 4 for CVE-2026-86218 in on-premises N-central installations. The vendor’s incident notice now reports exploitation in the wild, but its release notes remain contradictory.

N-able released N-central Hotfix 4 for the critical CVE-2026-86218 vulnerability in the on-premises N-central platform. It is a pre-authentication flaw enabling remote code execution, meaning an attack without prior login. N-able’s new incident notice also states that a separate new vulnerability was observed being exploited in the wild.
The fix is available as N-central 2026.3 Hotfix 4, build 2026.3.1.14. It replaces the previous Hotfix 3, and organizations that already deployed build 2026.3.1.13 must also update. According to the vendor, hosted NCOD instances have already been fixed; the customer update applies to on-premises deployments.
N-central Hotfix 4 for On-Premises Servers
CVE-2026-86218 affects the N-central RMM console used for remote management of IT environments. Compromise of such a server could allow an attacker to affect the management of a large number of endpoints. N-able therefore released Hotfix 4 as the current fix for on-premises servers.
On-premises installations running versions before build 2026.3.1.14 are affected. An independent NHS England security alert also points to the need to deploy this fix version. Administrators should verify the current build of their N-central server and move to 2026.3.1.14 if they are not already using it.
Contradictory Statements on Exploitation
N-able’s communications still contain a significant contradiction. The vendor’s active incident notice explicitly says that a separate new vulnerability was observed being exploited in the wild. The Hotfix 4 release notes, by contrast, still state that N-able has no confirmation that this vulnerability was exploited in production environments.
It has not been publicly clarified why these two statements differ or which represents the company’s current position on CVE-2026-86218. The attackers’ identity, the number of affected organizations, and the complete attack chain have also not been confirmed.
In addition, Huntress was unable to confirm from available historical logs that the compromise of one customer on September 4, 2026, was caused specifically by CVE-2026-86218. It also allows for a possible connection to CVE-2026-86206 or CVE-2026-86207.
What Administrators Should Do
- Verify the version of the on-premises N-central server.
- Deploy build 2026.3.1.14, or N-central Hotfix 4, even if Hotfix 3 was previously installed.
- According to N-able, no customer update is required for hosted NCOD.
Further information may concern the alignment of N-able’s statements on active exploitation, technical details, indicators of compromise, and the scope of affected on-premises deployments.
Sources
- N-able — 2026.3 HF4 Release Notes – Confirms the release of Hotfix 4/build 2026.3.1.14, pre-authentication RCE, replacement of HF3, the need to patch on-premises deployments, and the NCOD fix; it also states that exploitation in production has not been confirmed.
- N-able Uptime — URGENT: N-CENTRAL IMMEDIATE HOTFIX REQUIRED – N-able’s primary incident notice states that a separate new vulnerability was observed being exploited in the wild.
- Huntress — Critical N-able N-central Vulnerability and Active Exploitation – Documents the contradiction between the incident notice and release notes and states that Huntress cannot retrospectively attribute the compromise specifically to CVE-2026-86218.
- NHS England — Active Exploitation of Critical N-central Unauthenticated RCE Vulnerability – The independent public security alert confirms versions affected before 2026.3.1.14 and the urgency of deploying Hotfix 4.
Verified and updated: 09/08/2026 06:22



