Patch N-central Again: Hotfix 4 Is Out
N-able's fourth N-central hotfix in five weeks renders Hotfix 3 obsolete. Update to 2026.3.1.14 now: CVE-2026-86218 is actively exploited.

If you patched N-central yesterday, patch it again.
N-able released Hotfix 4 for N-central today, September 7. The Hacker News reports that every on-premises N-central build below version 2026.3.1.14 is still vulnerable, including builds updated to Hotfix 3 just one day earlier. Hotfix 3 is now obsolete. The target version is 2026.3.1.14.
The underlying flaw is CVE-2026-86218: a pre-authentication remote code execution rated at CVSS 10.0, requiring no credentials and reachable over the network. N-able’s incident notice states the flaw has been exploited in the wild. This is the fourth emergency hotfix for N-central in five weeks.
Exploitation was confirmed this morning. N-central controls MSP infrastructure: script execution, patch deployment, and monitoring across every managed client endpoint. A compromised N-central server means immediate, simultaneous access to the whole managed fleet. Ransomware operators have targeted RMM platforms for exactly this reason.
There are no workarounds. N-able’s advisory documents no mitigations short of isolating the server from external network access. The September 6 disclosure writeup has the full technical background on the flaw.
Check your installed version at System > Updates. If you are not on 2026.3.1.14, that is the only task that matters right now.
- [ CRITICAL ]CVE-2026-86218N-central Pre-Authentication Remote Code Execution
Found this useful? Share it.


