Skip to content
feed: live
>_0dayNews
supply chain

Patch N-central Again: Hotfix 4 Is Out

N-able's fourth N-central hotfix in five weeks renders Hotfix 3 obsolete. Update to 2026.3.1.14 now: CVE-2026-86218 is actively exploited.

Patch N-central Again: Hotfix 4 Is Out
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
fuseMarisol "Fuse" Delgado·Published ·1 min read

If you patched N-central yesterday, patch it again.

N-able released Hotfix 4 for N-central today, September 7. The Hacker News reports that every on-premises N-central build below version 2026.3.1.14 is still vulnerable, including builds updated to Hotfix 3 just one day earlier. Hotfix 3 is now obsolete. The target version is 2026.3.1.14.

The underlying flaw is CVE-2026-86218: a pre-authentication remote code execution rated at CVSS 10.0, requiring no credentials and reachable over the network. N-able’s incident notice states the flaw has been exploited in the wild. This is the fourth emergency hotfix for N-central in five weeks.

Exploitation was confirmed this morning. N-central controls MSP infrastructure: script execution, patch deployment, and monitoring across every managed client endpoint. A compromised N-central server means immediate, simultaneous access to the whole managed fleet. Ransomware operators have targeted RMM platforms for exactly this reason.

There are no workarounds. N-able’s advisory documents no mitigations short of isolating the server from external network access. The September 6 disclosure writeup has the full technical background on the flaw.

Check your installed version at System > Updates. If you are not on 2026.3.1.14, that is the only task that matters right now.

Related CVEs
  • [ CRITICAL ]CVE-2026-86218N-central Pre-Authentication Remote Code Execution

Found this useful? Share it.