CISA Adds Critical N-able N-central Flaw to KEV; Hotfix 4 Available
CISA added CVE-2026-86218 in the N-able N-central platform to its catalog of actively exploited vulnerabilities. Hotfix 4 is available for on-premises deployments.

N-central Hotfix 4 addresses the critical CVE-2026-86218 vulnerability in the N-able N-central tool. On September 8, 2026, the U.S. agency CISA added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, which collects vulnerabilities considered to be exploited. The flaw could allow remote code execution on a server without prior authentication.
N-able says that N-central versions older than build 2026.3.1.14 are affected. The vendor therefore released N-central 2026.3 Hotfix 4, designated as build 2026.3.1.14. It recommends that organizations with their own, meaning on-premises, deployments update immediately. Hosted NCOD instances have already received the fix, according to N-able.
N-central Hotfix 4 for on-premises servers
N-central is a remote monitoring and management (RMM) platform used by administrators and IT service providers to monitor and manage devices. A vulnerability on such a server is more severe partly because an RMM system may manage a large number of customer devices.
If CVE-2026-86218 were successfully exploited, an attacker could execute code on an N-central server without authentication. In its notice, N-able identified fixed build 2026.3.1.14 as the cutoff for affected versions. For administrators of their own installations, the specific step is therefore to deploy Hotfix 4, not merely check the product’s general version.
When adding the flaw to KEV, CISA refers to following the vendor’s instructions. The catalog is intended for flaws for which the agency has sufficient basis to designate them as being exploited in the wild.
Communication about exploitation is not entirely consistent
The exploitation status of CVE-2026-86218 is accompanied by a discrepancy in the currently available communications. N-able’s Hotfix 4 release notes from September 5 and 6 stated that the company had no confirmed exploitation of the vulnerability in production environments.
However, the Canadian Centre for Cyber Security states in its alert that N-able indicates exploitation of the flaw in the wild. Its subsequent addition to the CISA KEV catalog further underscores this status. However, the available information does not publicly confirm the number of affected organizations or the identities of specific attackers.
Researchers from Huntress also pointed out limitations in the retrospective analysis of an earlier compromise. Due to a lack of historical logs, they could not conclusively attribute it specifically to CVE-2026-86218. This circumstance does not refute the flaw’s inclusion in KEV, but it means that the public technical attribution of individual incidents is not settled.
What administrators should do
- Verify whether the organization’s own N-central server is running build 2026.3.1.14 or newer.
- If an older version is deployed, promptly apply N-central Hotfix 4 according to N-able’s instructions.
- Examine the environment for possible prior compromise, since installing the fix alone does not rule it out.
- Monitor further notices from N-able, CISA, and trusted security researchers, especially any indicators of compromise and forensic guidance.
An updated N-able statement on confirmed exploitation in production and the possible release of additional technical details can be expected in particular. The scope of the incidents and attribution of the attacks to a specific actor have not yet been publicly confirmed.
Sources
- CISA Known Exploited Vulnerabilities Catalog – Confirms the addition of CVE-2026-86218 to the KEV catalog on September 8, 2026, and the requirement to follow the vendor’s instructions.
- N-able Status – N-central 2026.3 Hotfix 4 – Confirms the release of Hotfix 4, build 2026.3.1.14, the nature of the flaw, the recommendation for on-premises deployments, and the status of hosted NCOD instances.
- N-able 2026.3 HF4 Release Notes – Confirms the affected versions before 2026.3.1.14 and records N-able’s statement at the time that it had no confirmed exploitation in production.
- Canadian Centre for Cyber Security – AV26-885 – Reports active exploitation according to N-able and records the addition of the CVE to CISA KEV.
- Huntress – Documents the conflict between N-able’s communications about exploitation and the release notes, as well as limitations in attributing the earlier compromise to a specific CVE.
Verified and updated: 09. 09. 2026 06:22



