N-able ships N-central hotfix for critical RCE
N-able Status posted N-central 2026.3 Hotfix 4, build 2026.3.1.14, for CVE-2026-86218, a critical pre-authenticated remote code execution bug. Self-hosted servers must upgrade now, hosted NCOD is already patched, and N-able reports no confirmed production exploitation.

N-able posted a status notice for N-central 2026.3 Hotfix 4, last updated 5 September 2026. The build is 2026.3.1.14. It closes CVE-2026-86218, a critical-CVSS vulnerability that could allow pre-authenticated remote code execution on the N-central server.
This is a vendor status-page security update, with matching HF4 release notes. It is not a CISA Known Exploited Vulnerabilities listing.
The bug was responsibly disclosed by a third party through N-able's security disclosure program. N-able says it has no confirmations that the vulnerability has been exploited in production environments, but unpatched systems remain at risk.
On-premises and self-hosted customers must upgrade to 2026.3 HF4 (2026.3.1.14) immediately. Hosted N-central (NCOD) already has the patches applied, and those customers have no action.
The hotfix supersedes HF3 build 2026.3.1.13. Direct upgrade paths run from 2025.4, 2026.1, 2026.2, 2026.3, and earlier 2026.3.1 hotfixes. Agents do not need to be upgraded for this CVE.
BleepingComputer cites Shadowserver tracking nearly 1,500 N-central servers exposed online, mostly in the United States and Europe. Huntress flagged CVE-2026-86218 as a potential zero-day alongside CVE-2026-86206 and CVE-2026-86207, two auth-bypass bugs patched over the weekend in HF3. Huntress could not confirm which CVE hit a customer production environment because logs on that server had already rotated. It warns that HF3 remains vulnerable to the new RCE, so on-premises operators still need HF4.
N-able's line is no confirmed production exploitation. Huntress treats the new bug as a potential zero-day and cannot attribute that earlier compromise to a specific CVE. Those two statements can sit together. Neither source has documented a confirmed mass exploitation campaign.
RMM consoles keep drawing the same internet-facing risk as a MikroTik SSH takeover chain, a ScreenConnect guest file-transfer worm, and a JFrog Artifactory auth bypass. A Magento storefront RCE such as StyleSmuggler is a different product class, but it is the same lesson: patch the management plane before it becomes the door.
If you run self-hosted N-central, upgrade to build 2026.3.1.14 today. Hosted NCOD can stand down. Hunt for unusual pre-auth activity even if N-able has not confirmed production exploitation, because HF3 is not enough and Huntress could not rule a prior customer hit in or out after the logs rotated.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free