N-central Security Hotfix – September 5, 2026
Earlier today, N-able released N-central 2026.3 HF3, a security-focused hotfix addressing CVE-2026-86206 and CVE-2026-86207, two vulnerabilities identified through responsible disclosure by security researchers at Rapid7 Labs and Huntress.
Following receipt of the reports, N-able’s Engineering and Security teams worked closely with the researchers to validate the findings, assess potential impact, and develop remediations. We appreciate the responsible disclosure process followed by both organizations, which enabled us to investigate and address these vulnerabilities before details became broadly available.
Important: At this time, we have no confirmations that the vulnerabilities have been exploited.
Vulnerability Details
- CVE-2026-86206 – Access control filter bypass allows unauthorised access to internal N-central APIs (CVSS 6.9)
- CVE-2026-86207 – Authentication bypass leads to unauthorised access to N-central (CVSS 7.7)
Additional technical details are available in the associated security advisories and CVE records.
What You Need to Do
- N-central On-Premises Environments: We recommend upgrading to 2026.3 HF3 immediately. Hotfix link: 2026.3 HF3 Release Notes
- N-central Hosted Environments: No action is needed on your part; your instances have already been patched and will be upgraded at a later time.
We recognize that many customers may be managing reduced staffing and planned activities over the holiday weekend. However, given the importance of these security updates, the recent focus on N-central security, and our commitment to transparency, we believe it is in our customers’ best interest to make the hotfix available immediately rather than delay distribution until the next business day.
While these vulnerabilities were identified through responsible disclosure rather than active exploitation, security updates are most effective when applied before threat actors have an opportunity to incorporate newly disclosed information into their operations. For that reason, we encourage customers to apply this update at the earliest practical opportunity.
Our Commitment
At N-able, helping customers maintain secure and resilient environments remains our highest priority. We are committed to acting quickly on credible security research, providing timely guidance, and maintaining transparency throughout the vulnerability management process.
We thank the research teams at Rapid7 Labs and Huntress for their partnership and responsible disclosure of these findings.
If you need assistance applying this update or have questions regarding your N-central environment, please contact N-able Support https://me.n-able.com/
© N‑able Solutions ULC and N‑able Technologies Ltd. All rights reserved.
This document is provided for informational purposes only and should not be relied upon as legal advice. N‑able makes no warranty, express or implied, or assumes any legal liability or responsibility for the accuracy, completeness, or usefulness of any information contained herein.
The N-ABLE, N-CENTRAL, and other N‑able trademarks and logos are the exclusive property of N‑able Solutions ULC and N‑able Technologies Ltd. and may be common law marks, are registered, or are pending registration with the U.S. Patent and Trademark Office and with other countries. All other trademarks mentioned herein are used for identification purposes only and are trademarks (and may be registered trademarks) of their respective companies.