N-central Security Update – Take Action to Apply 2026.3 HF4

UPDATE PUBLISHED: 9/6/2026, 4:30 AM UTC

As we shared in yesterday’s blog post, two security vulnerabilities within N-central were responsibly disclosed by a third party through our voluntary security disclosure program, and we issued a hotfix to address them. Since our post 9/5/2026, 08:11:00 UTC a third independent researcher disclosed to N-able a new vulnerability— one that has been exploited in the wild and is unrelated to the previously disclosed CVEs.

This critical zero-day vulnerability, CVE-2026-86218, could allow pre-authenticated access to the N-central server if exploited.

We communicated this hotfix earlier today, and we want to use this post as a reminder to upgrade immediately if you haven’t already, so we can help keep you and your customers protected.

What You Need to Do

  • N-central On-Premises Environments: Apply 2026.3 HF4 immediately. Get started here: 2026.3 HF4 Release Notes
    • Already on 2026.3 HF3? You’ll still need to upgrade to HF4 to be protected against this newly discovered vulnerability.
  • N-central Hosted Environments: No action needed on your end; your instance has already been patched.

Please note this is a server-side hotfix, so upgrading to 2026.3 HF4 will not require any agent upgrades.

How to Check for Indicators of Compromise

Take the following steps to check whether your environment may have been affected:

  1. Review your logs for scanning activity. We’ve observed scans originating from the IP range 23.234.64.0/18 attempting to exploit this vulnerability. Check your logs for any connections from this range.
  2. Audit your user accounts. Look for any recently created accounts you don’t recognize, paying close attention to:
    • Accounts using a .invalid email address
    • Email addresses with unusual character substitutions or string manipulations designed to look legitimate at a glance
  3. Reach out if you spot anything suspicious. If you find evidence of the activity above, or have any other concerns, contact N-able Support right away so we can help you investigate further.

 

PUBLISHED: 9/5/2026, 8:18 PM UTC

Earlier today, N-able released N-central 2026.3 HF3, a security-focused hotfix addressing CVE-2026-86206 and CVE-2026-86207, two vulnerabilities identified through responsible disclosure by security researchers at Rapid7 Labs and Huntress.

Following receipt of the reports, N-able’s Engineering and Security teams worked closely with the researchers to validate the findings, assess potential impact, and develop remediations. We appreciate the responsible disclosure process followed by both organizations, which enabled us to investigate and address these vulnerabilities before details became broadly available.

Important: At this time, we have no confirmations that the vulnerabilities have been exploited.

Vulnerability Details

  • CVE-2026-86206 – Access control filter bypass allows unauthorised access to internal N-central APIs (CVSS 6.9)
  • CVE-2026-86207 – Authentication bypass leads to unauthorised access to N-central (CVSS 7.7)

Additional technical details are available in the associated security advisories and CVE records.

What You Need to Do

  • N-central On-Premises Environments: We recommend upgrading to 2026.3 HF3 immediately.  Hotfix link: 2026.3 HF3 Release Notes
  • N-central Hosted Environments: No action is needed on your part; your instances have already been patched and will be upgraded at a later time.

We recognize that many customers may be managing reduced staffing and planned activities over the holiday weekend. However, given the importance of these security updates, the recent focus on N-central security, and our commitment to transparency, we believe it is in our customers’ best interest to make the hotfix available immediately rather than delay distribution until the next business day.

While these vulnerabilities were identified through responsible disclosure rather than active exploitation, security updates are most effective when applied before threat actors have an opportunity to incorporate newly disclosed information into their operations. For that reason, we encourage customers to apply this update at the earliest practical opportunity.

Our Commitment

At N-able, helping customers maintain secure and resilient environments remains our highest priority. We are committed to acting quickly on credible security research, providing timely guidance, and maintaining transparency throughout the vulnerability management process.

We thank the research teams at Rapid7 Labs and Huntress for their partnership and responsible disclosure of these findings.

If you need assistance applying this update or have questions regarding your N-central environment, please contact N-able Support https://me.n-able.com/

    © N‑able Solutions ULC and N‑able Technologies Ltd. All rights reserved.

    This document is provided for informational purposes only and should not be relied upon as legal advice. N‑able makes no warranty, express or implied, or assumes any legal liability or responsibility for the accuracy, completeness, or usefulness of any information contained herein.

    The N-ABLE, N-CENTRAL, and other N‑able trademarks and logos are the exclusive property of N‑able Solutions ULC and N‑able Technologies Ltd. and may be common law marks, are registered, or are pending registration with the U.S. Patent and Trademark Office and with other countries. All other trademarks mentioned herein are used for identification purposes only and are trademarks (and may be registered trademarks) of their respective companies.