N-able Releases Fourth Critical Hotfix for Unauthenticated RCE Vulnerability in N-Central Platform
N-able released its fourth hotfix in five weeks for the N-central RMM platform to address a critical unauthenticated remote code execution (RCE) vulnerability (CVE-2026-86218) with a CVSS score of 10.0, while conflicting reports about real-world exploitation persist. The flaw affects all on-premises N-central builds prior to 2026.3.1.14, requiring immediate patching despite unclear evidence of active exploitation.
Every on-premises N-central build below 2026.3.1.14 — including servers updated to Hotfix 3 a day earlier — needs Hotfix 4. N-able's incident notice says the flaw has been exploited in the wild; its release notes say that is unconfirmed.
N-able has released its fourth hotfix in five weeks for the N-central remote monitoring and management (RMM) platform, this time for a
*** END OF TRANSMISSION ***