Particle.news
Download on the App Store

N-able Issues Emergency Hotfix for Pre-Auth RCE in N-central

Assigned a 10.0 severity score, the flaw lets unauthenticated attackers run code on exposed N-central servers and reach managed endpoints.

Overview

  • N-able released N-central 2026.3 Hotfix 4 on Saturday to fix CVE-2026-86218 and urged on-premises customers to upgrade immediately while saying hosted instances have been patched.
  • The vulnerability is a pre-authentication remote code execution bug that N-able assigned a 10.0 CVSS score and described as a static code injection weakness.
  • Public messages from N-able conflict over whether the bug has been seen exploited in the wild, and Huntress says it cannot confirm exploitation in a recent customer compromise because server logs had already rotated.
  • Security researchers and Shadowserver report roughly 1,500 internet-exposed N-central servers, mostly in the U.S. and Europe, and vendors advise restricting console access with IP allowlists or a VPN or taking internet-facing instances offline until patched.
  • This is the fourth hotfix for the 2026.3 line in five weeks after a July 31 intrusion that let attackers pivot from the management console to managed endpoints, raising urgent risk for MSPs and their customers.