N-central Security Hotfix – September 5, 2026

Earlier today, N-able released N-central 2026.3 HF3, a security-focused hotfix addressing CVE-2026-86206 and CVE-2026-86207, two vulnerabilities identified through responsible disclosure by security researchers at Rapid7 Labs and Huntress.

Following receipt of the reports, N-able’s Engineering and Security teams worked closely with the researchers to validate the findings, assess potential impact, and develop remediations. We appreciate the responsible disclosure process followed by both organizations, which enabled us to investigate and address these vulnerabilities before details became broadly available.

Important: At this time, we have no confirmations that the vulnerabilities have been exploited.

Vulnerability Details

  • CVE-2026-86206 – Access control filter bypass allows unauthorised access to internal N-central APIs (CVSS 6.9)
  • CVE-2026-86207 – Authentication bypass leads to unauthorised access to N-central (CVSS 7.7)

Additional technical details are available in the associated security advisories and CVE records.

What You Need to Do

  • N-central On-Premises Environments: We recommend upgrading to 2026.3 HF3 immediately.  Hotfix link: 2026.3 HF3 Release Notes
  • N-central Hosted Environments: No action is needed on your part; your instances have already been patched and will be upgraded at a later time.

We recognize that many customers may be managing reduced staffing and planned activities over the holiday weekend. However, given the importance of these security updates, the recent focus on N-central security, and our commitment to transparency, we believe it is in our customers’ best interest to make the hotfix available immediately rather than delay distribution until the next business day.

While these vulnerabilities were identified through responsible disclosure rather than active exploitation, security updates are most effective when applied before threat actors have an opportunity to incorporate newly disclosed information into their operations. For that reason, we encourage customers to apply this update at the earliest practical opportunity.

Our Commitment

At N-able, helping customers maintain secure and resilient environments remains our highest priority. We are committed to acting quickly on credible security research, providing timely guidance, and maintaining transparency throughout the vulnerability management process.

We thank the research teams at Rapid7 Labs and Huntress for their partnership and responsible disclosure of these findings.

If you need assistance applying this update or have questions regarding your N-central environment, please contact N-able Support https://me.n-able.com/

    © N‑able Solutions ULC e N‑able Technologies Ltd. Todos os direitos reservados.

    Este documento é fornecido apenas para fins informativos e não deve servir de base para aconselhamento jurídico. A N‑able não oferece nenhuma garantia, expressa ou implícita, nem assume qualquer responsabilidade legal ou responsabilidade pela precisão, integralidade ou utilidade de qualquer informação nele contido.

    As marcas N-ABLE, N-CENTRAL e outras marcas registradas e logotipos N‑able são de propriedade exclusiva da N‑able Solutions ULC e da N‑able Technologies Ltd e podem ser marcas legais comuns, registradas ou de registro pendente com o Escritório de Marcas e Patentes dos EUA e com outros países. Todas as outras marcas comerciais mencionadas neste documento são usadas apenas para fins de identificação e são marcas comerciais (e poderão ser marcas registradas) de suas respectivas empresas.