N-central Security Update – Take Action to Apply 2026.3 HF4
UPDATE PUBLISHED: 9/9/2026, 1:49 PM UTC
Please note that we have an update on exploits.
At the time of the hotfix, an independent researcher reported a successful exploit within their own production environment; we had no confirmed cases of exploitation among N-central customers. Since then, we’ve observed a handful of successful exploits against N-central customers. We are continuing to investigate and are working directly with any customer who reports suspicious activity.
We also continue to encourage customers who are not upgraded to 2026.3 HF4 to do so immediately to help ensure they are protected.
UPDATE PUBLISHED: 9/6/2026, 4:30 AM UTC
As we shared in yesterday’s blog post, two security vulnerabilities within N-central were responsibly disclosed by a third party through our voluntary security disclosure program, and we issued a hotfix to address them. Since our post 9/5/2026, 08:11:00 UTC a third independent researcher disclosed to N-able a new vulnerability— one that has been exploited in the wild and is unrelated to the previously disclosed CVEs.
This critical zero-day vulnerability, CVE-2026-86218, could allow pre-authenticated access to the N-central server if exploited.
We communicated this hotfix earlier today, and we want to use this post as a reminder to upgrade immediately if you haven’t already, so we can help keep you and your customers protected.
What You Need to Do
- N-central On-Premises Environments: Apply 2026.3 HF4 immediately. Get started here: 2026.3 HF4 Release Notes
- Already on 2026.3 HF3? You’ll still need to upgrade to HF4 to be protected against this newly discovered vulnerability.
- N-central Hosted Environments: No action needed on your end; your instance has already been patched.
Please note this is a server-side hotfix, so upgrading to 2026.3 HF4 will not require any agent upgrades.
How to Check for Indicators of Compromise
Take the following steps to check whether your environment may have been affected:
- Review your logs for scanning activity. We’ve observed scans originating from the IP range 23.234.64.0/18 attempting to exploit this vulnerability. Check your logs for any connections from this range.
- Audit your user accounts. Look for any recently created accounts you don’t recognize, paying close attention to:
- Accounts using a .invalid email address
- Email addresses with unusual character substitutions or string manipulations designed to look legitimate at a glance
- Reach out if you spot anything suspicious. If you find evidence of the activity above, or have any other concerns, contact N-able Support right away so we can help you investigate further.
PUBLISHED: 9/5/2026, 8:18 PM UTC
Earlier today, N-able released N-central 2026.3 HF3, a security-focused hotfix addressing CVE-2026-86206 and CVE-2026-86207, two vulnerabilities identified through responsible disclosure by security researchers at Rapid7 Labs and Huntress.
Following receipt of the reports, N-able’s Engineering and Security teams worked closely with the researchers to validate the findings, assess potential impact, and develop remediations. We appreciate the responsible disclosure process followed by both organizations, which enabled us to investigate and address these vulnerabilities before details became broadly available.
Important: At this time, we have no confirmations that the vulnerabilities have been exploited.
Vulnerability Details
- CVE-2026-86206 – Access control filter bypass allows unauthorised access to internal N-central APIs (CVSS 6.9)
- CVE-2026-86207 – Authentication bypass leads to unauthorised access to N-central (CVSS 7.7)
Additional technical details are available in the associated security advisories and CVE records.
What You Need to Do
- N-central On-Premises Environments: We recommend upgrading to 2026.3 HF3 immediately. Hotfix link: 2026.3 HF3 Release Notes
- N-central Hosted Environments: No action is needed on your part; your instances have already been patched and will be upgraded at a later time.
We recognize that many customers may be managing reduced staffing and planned activities over the holiday weekend. However, given the importance of these security updates, the recent focus on N-central security, and our commitment to transparency, we believe it is in our customers‘ best interest to make the hotfix available immediately rather than delay distribution until the next business day.
While these vulnerabilities were identified through responsible disclosure rather than active exploitation, security updates are most effective when applied before threat actors have an opportunity to incorporate newly disclosed information into their operations. For that reason, we encourage customers to apply this update at the earliest practical opportunity.
Our Commitment
At N-able, helping customers maintain secure and resilient environments remains our highest priority. We are committed to acting quickly on credible security research, providing timely guidance, and maintaining transparency throughout the vulnerability management process.
We thank the research teams at Rapid7 Labs and Huntress for their partnership and responsible disclosure of these findings.
If you need assistance applying this update or have questions regarding your N-central environment, please contact N-able Support https://me.n-able.com/
© N‑able Solutions ULC und N‑able Technologies Ltd. Alle Rechte vorbehalten.
Dieses Dokument dient nur zu Informationszwecken und stellt keine Rechtsberatung dar. N‑able übernimmt weder ausdrücklich noch stillschweigend Gewähr noch Haftung oder Verantwortung für Korrektheit, Vollständigkeit oder Nutzen der in diesem Dokument enthaltenen Informationen.
N-ABLE, N-CENTRAL und andere Marken und Logos von N‑able sind ausschließlich Eigentum von N‑able Solutions ULC und N‑able Technologies Ltd. Sie sind gesetzlich geschützte Marken und möglicherweise beim Patent- und Markenamt der USA und in anderen Ländern registriert oder zur Registrierung angemeldet. Alle anderen hier genannten Marken dienen ausschließlich zu Informationszwecken und sind Marken (oder registrierte Marken) der entsprechenden Unternehmen.