N-able issues hotfix for N-central zero-day RCE

N-able issued an urgent hotfix for a pre-authenticated RCE zero-day, CVE-2026-86218 (CVSS 10.0). On-premises users must install 2026.3 HF4; hosted instances were patched server-side.

N-able released an urgent hotfix to address a pre-authenticated remote code execution vulnerability in its N-central endpoint management platform. The flaw is tracked as CVE-2026-86218 and carries a CVSS score of 10.0. Hosted N-central customers received server-side patches; on-premises customers must install hotfix 2026.3 HF4. A mature vulnerability management process helps organizations prioritize emergency patches for internet-facing systems when severity, exploitability and business impact converge.

The hotfix replaces two earlier patches for CVE-2026-86206 and CVE-2026-86207. N-able warned that systems that remain unpatched could be subject to exploitation and urged administrators to apply HF4 to on-premises appliances without delay.

Security firm Huntress reported observing attacks against N-central’s API and appliance logs beginning on September 4, 2026. Huntress had previously flagged the earlier CVEs as possibly being chained by attackers to bypass authentication and compromise production environments. The firm noted that limited historical logging on the appliances prevents a definitive determination of which exploit was used and does not rule out the use of other vulnerabilities.

N-able’s advisory instructs customers to review logs for scanning activity and to check for connections from the IP range 23.234.64.0/18, which the vendor observed attempting exploitation. Administrators were also advised to look for any newly created user accounts they do not recognize.

The vendor provided log-review steps and connection checks in its advisory. Hosted customers do not need to take action because fixes were applied server-side; on-premises users must manually install 2026.3 HF4. N-able indicated it will continue to monitor and investigate reports of exploitation.

Articles by this author