N-able Releases Hotfix for Critical RCE Vulnerability in N-central Platform
N-able has issued a critical hotfix for its N-central platform to address CVE-2026-86218, a pre-authenticated remote code execution vulnerability that could allow attackers to compromise managed systems.

N-able has released N-central 2026.3 Hotfix 4 (build 2026.3.1.14) to address CVE-2026-86218, a critical pre-authenticated remote code execution vulnerability. This flaw allows unauthenticated attackers to execute arbitrary commands on exposed N-central servers, posing a significant risk to the downstream systems managed by IT teams and managed service providers.
The hotfix is specifically for on-premises N-central deployments, and N-able strongly urges self-hosted customers to install it immediately. The company has not confirmed exploitation in the wild, but emphasizes that delaying the patch leaves systems vulnerable to potential attacks. The severity of the vulnerability stems from the platform's extensive access, which can include endpoints, networks, credentials, and administrative tools.
CVE-2026-86218 enables an attacker to execute commands on the N-central server without needing to log in or provide any credentials. Successful exploitation could grant attackers control over the central management server, opening the door to deploying malware, altering monitoring configurations, stealing sensitive data, creating unauthorized accounts, or pivoting further into customer environments.
While N-able has not publicly disclosed the exact technical details or attack vector for CVE-2026-86218, they confirmed that the vulnerability was responsibly reported by a third party. Despite the absence of confirmed exploitation, organizations are advised not to delay patching. Publicly disclosed vulnerabilities can often spur threat actors to develop and deploy exploits.
Customers running N-central versions 2025.4, 2026.1, 2026.2, 2026.3, 2026.3.1 Hotfix 1, or 2026.3.1 Hotfix 2 can upgrade directly to the latest hotfix, build 2026.3.1.14. Those on older releases should first upgrade to a supported version before applying the hotfix.
N-able confirmed that their hosted N-central customers (NCOD users) do not need to take any action, as the necessary patches have already been applied to their environments. The urgent call to action is directed solely at organizations managing their own self-hosted N-central infrastructure.
Additionally, N-able stated that N-central agents do not require specific updates to address CVE-2026-86218. However, they recommend keeping agents updated as a general security best practice. Security teams are advised to identify all self-hosted N-central instances, verify their current build number, and schedule the update to build 2026.3.1.14 as soon as possible.
As a precautionary measure, administrators should review server access logs, administrator account activity, remote command execution records, and any unusual configuration changes for signs of suspicious behavior, both before and after applying the patch.
N-able has issued a fourth hotfix, 2026.3.1.14, for its N-central RMM platform to address a critical unauthenticated remote code execution vulnerability, CVE-2026-86218. This new hotfix is necessary for all on-premises N-central builds prior to this version, including those updated to the previous hotfix. While N-able's incident notice suggests the flaw has been exploited in the wild, its release notes state this remains unconfirmed, creating a divergence in official communications.