Full Report
Every on-premises N-central build below 2026.3.1.14 — including servers updated to Hotfix 3 a day earlier — needs Hotfix 4. N-able's incident notice says the flaw has been exploited in the wild; its release notes say that is unconfirmed. N-able has released its fourth hotfix in five weeks for the N-central remote monitoring and management (RMM) platform, this time for a
Analysis Summary
# Vulnerability: N-able N-central Unauthenticated Remote Code Execution (Hotfix 4)
## CVE Details
- **CVE ID:** CVE-2026-86218
- **CVSS Score:** 10.0 (Critical)
- **CWE:** CWE-96 (Improper Control of Generation of Code - 'Static Code Injection')
## Affected Systems
- **Products:** N-able N-central Remote Monitoring and Management (RMM) platform (On-premises).
- **Versions:** Every build below **2026.3.1.14**. This includes servers recently updated to Hotfix 3 (2026.3.1.13).
- **Configurations:** On-premises deployments are vulnerable. Hosted N-central (NCOD) instances have already been patched by the vendor.
## Vulnerability Description
CVE-2026-86218 is a maximum-severity static code injection flaw. It allows an unauthenticated remote attacker to execute arbitrary code on the N-central server. The flaw was identified by a third-party researcher and is distinct from previous vulnerabilities addressed in earlier hotfixes.
## Exploitation
- **Status:** **Exploited in the Wild** (Note: Confirmed in N-able's incident notice, though release notes describe it as "unconfirmed").
- **Complexity:** Low (Implicitly, due to the CVSS 10.0 rating and unauthenticated RCE nature).
- **Attack Vector:** Network (Remote).
## Impact
- **Confidentiality:** Total (Critical)
- **Integrity:** Total (Critical)
- **Availability:** Total (Critical)
## Remediation
### Patches
- **Upgrade to N-central version 2026.3.1.14 (Hotfix 4) immediately.**
- Direct upgrade paths are available from versions 2025.4, 2026.1, 2026.2, 2026.3, and all 2026.3.1 hotfixes.
- RMM Agents do not require an upgrade to protect against this specific CVE.
### Workarounds
- **Network Access Control:** Restrict inbound access to the N-central console using IP allowlisting or a VPN.
- **Server Isolation:** If the server is internet-facing and cannot be patched immediately, take it offline until the hotfix is applied.
## Detection
- **Account Auditing:** Review N-central user accounts for any unexpected or unauthorized users.
- **Log Review:** Monitor for unusual activity, though some researchers (Huntress) note that logs may rotate quickly, potentially hiding exploitation attempts.
## References
- **N-able Status Post:** [https://status.n-able.com/2026/09/06/n-central-2026-3-hotfix-4-cve-2026-86218/](https://status.n-able.com/2026/09/06/n-central-2026-3-hotfix-4-cve-2026-86218/)
- **N-able Incident Notice:** [https://uptime.n-able.com/event/201814/](https://uptime.n-able.com/event/201814/)
- **N-able Release Notes:** [https://documentation.n-able.com/N-central/Release_Notes/GA/Content/N-central_2026.3_HF4_Release_Notes.htm](https://documentation.n-able.com/N-central/Release_Notes/GA/Content/N-central_2026.3_HF4_Release_Notes.htm)
- **Huntress Research:** [https://www.huntress.com/blog/n-able-vulnerability-exploitation](https://www.huntress.com/blog/n-able-vulnerability-exploitation)