N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw
- ID
- 22069
- Status
- summarized
- Published
- 07 Sep 2026, 4:31 PM
- Fetched
- 07 Sep 2026, 6:38 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/n-able-issues-fourth-n-central-hotfix.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 2.5
- Created
- 07 Sep 2026, 6:39 PM
- Tags
- Audience
- developers
What happened
N-able released its fourth hotfix in five weeks for N-central, an on-premises RMM platform, patching CVE-2026-86218 — a CVSS 10.0 unauthenticated remote code execution flaw (CWE-96 static code injection) affecting every build before 2026.3.1.14. N-able's own communications conflict on whether the flaw has been exploited in the wild, with incident notices suggesting exploitation and release notes saying it is unconfirmed; no IOCs or mitigations were provided beyond auditing for unexpected users.
Why it matters
If you or your MSP runs on-premises N-central, upgrade to 2026.3.1.14 immediately and restrict console access via IP allowlisting or VPN — Huntress reports active attacks since August. For everyone else, this is not actionable; it is a niche RMM platform, not a tool this audience typically ships with.
Discussion angle
The vendor's own channels disagreeing on whether exploitation occurred — and shipping four hotfixes in five weeks with no IOCs — is a case study in how not to communicate during an active security incident.