N-able has issued Hotfix 4 for N-central to patch CVE-2026-86218, a maximum-severity pre-authentication remote code execution flaw affecting all on-premises builds before 2026.3.1.14. The company’s notices conflict on exploitation status, with one saying the issue has been observed in the wild while other release notes say there are no confirmations of production exploitation, prompting urgent updates and access restrictions. #Ncentral #CVE202686218 #Nable
Keypoints
- N-able released Hotfix 4 for N-central, covering builds before 2026.3.1.14.
- CVE-2026-86218 is a 10.0-rated flaw that may enable unauthenticated remote code execution.
- N-able’s incident notice says the vulnerability has been exploited in the wild, but its release notes dispute that claim.
- Hosted N-central instances are already patched, while on-premises customers must upgrade immediately.
- Huntress advises restricting console access and taking exposed servers offline until patched.
Read More: https://thehackernews.com/2026/09/n-able-issues-fourth-n-central-hotfix.html