N-able shipped N-central 2026.3 Hotfix 4 (build 2026.3.1.14) for CVE-2026-86218, a maximum-severity pre-authentication remote code execution flaw on the N-central server. The company rates it critical and tells on-premises customers to upgrade immediately. Hosted N-central (NCOD) instances were patched server-side — no customer action. Shadowserver has been tracking nearly 1,500 internet-exposed N-central servers, concentrated in the United States and Europe.
The exploitation story is split. N-able’s public status post says the issue was responsibly disclosed and that it has “no confirmations that this vulnerability has been exploited in production environments.” Separate reporting on customer notices and SecurityWeek coverage describe the flaw as observed in the wild and label it a zero-day. Huntress separately investigated a compromised, already-patched customer environment on September 4 and said rotated logs mean it cannot confirm which CVE the actor used. CyberMerge will not collapse those channels into a single confirmed-exploitation claim.
Context for MSP operators: HF4 supersedes Hotfix 3, which had just addressed CVE-2026-86206 and CVE-2026-86207 (auth bypass / unauthorized admin paths). N-able has also pointed defenders at scanning from IP range 23.234.64.0/18 and told admins to review logs and watch for unfamiliar local accounts. One compromised RMM console can cascade across client estates — that is the underwrite, not the CVE label.
The sourced facts: CVSS 10 pre-auth RCE, build 2026.3.1.14, on-prem must patch / hosted done, ~1,500 exposed consoles per Shadowserver, conflicting in-the-wild language across N-able channels, Huntress compromise without a definitive CVE attribution. Patch first. Argue attribution later.
