CVE Tools

N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw

The Hacker NewsBy The Hacker News

Reported exploitedN-central

Our summary

N-able has released Hotfix 4 for the N-central Remote Monitoring and Management platform to address a critical, pre-authentication remote code execution vulnerability identified as CVE-2026-86218. This flaw, which carries a CVSS score of 10.0 and allows unauthenticated attackers to execute arbitrary code on the server, has reportedly been actively exploited in the wild according to N-able's incident notice, although the company's official release notes currently state that such exploitation remains unconfirmed.

This update is particularly urgent because it supersedes Hotfix 3, meaning systems patched just one day prior to this release remain vulnerable. All on-premises installations running builds older than 2026.3.1.14 must be updated immediately to prevent unauthorized access and potential endpoint compromise. N-able advises administrators to restrict network exposure and audit user accounts while waiting for deployment completion, noting that hosted instances have already been secured.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store