N-able N-central HF4 Fixes Critical RCE After Series of Authentication Flaws
N-able has released N-central 2026.3 Hotfix 4 (build 2026.3.1.14) to fix CVE-2026-86218, a critical pre-authentication remote code execution vulnerability in its remote monitoring and management platform. The update supersedes three hotfixes issued between August 2 and September 5 and is the current security baseline for the 2026.3 branch.
The rapid sequence matters because the hotfixes address more than one weakness. Earlier releases responded to an actively exploited authentication bypass and later access control flaws, while HF4 closes a separate path to code execution. On-premises administrators should therefore install HF4 even if HF1, HF2, or HF3 is already present.
What Does N-central Hotfix 4 Fix?
CVE-2026-86218 affects N-central versions before 2026.3.1.14 and can allow an unauthenticated attacker to execute code on the N-central server. N-able classifies the issue as critical and describes it as a zero-day but has not publicly disclosed the affected component or exploitation method.

Details of CVE-2026-86218 (SOCRadar Vulnerability Intelligence)
According to N-able’s HF4 release notes, the company has no confirmed evidence that CVE-2026-86218 has been exploited in production environments. Unpatched, internet accessible systems should nevertheless be treated as high-priority remediation targets because exploitation does not require prior authentication.
Which Other N-central Vulnerabilities Matter?
HF4 sits at the end of a broader patch sequence. The following issues are relevant when assessing exposure and deciding how far back an investigation should look:
| Vulnerability | Severity/status | Security impact | Remediation |
|---|---|---|---|
| CVE-2026-86218 | Critical | Pre-authentication remote code execution | HF4 / 2026.3.1.14 |
| CVE-2026-86206 | High | Access-control filter bypass exposing internal APIs | HF3 or later |
| CVE-2026-86207 | High | Authentication bypass affecting internal only APIs | HF3 or later |
| CVE-2026-18577 | Known exploited | Authentication bypass and account takeover after an incomplete earlier fix | HF1, then HF2 hardening; superseded by HF4 |
| CVE-2026-18556 | Known exploited | Earlier authentication bypass affecting versions through 2026.1 | 2026.2 and later hotfix chain |
CVE-2026-18556 and CVE-2026-18577 are listed in CISA’s Known Exploited Vulnerabilities catalog. N-able’s HF2 notes explain that additional protection was introduced as continued monitoring identified a related attack path and evolving attacker techniques. By contrast, N-able says it has no confirmation that CVE-2026-86206 or CVE-2026-86207 was exploited in production.
Why Were Four Hotfixes Released So Quickly?
The releases reflect several distinct security problems rather than repeated packaging of one patch. HF1 addressed the initial authentication-bypass attack path associated with CVE-2026-18556 and CVE-2026-18577. HF2 added further protection after monitoring revealed a related attack path and evolving attacker techniques.
HF3 fixed two separately disclosed access-control vulnerabilities, CVE-2026-86206 and CVE-2026-86207. HF4 then addressed the separate pre-authentication RCE tracked as CVE-2026-86218.
This sequence also changes how teams should verify remediation. Checking that “2026.3” is installed is not enough: the original 2026.3 build predates all four hotfixes, and HF3 remains vulnerable to CVE-2026-86218. Administrators should verify the live server reports build 2026.3.1.14.
Which Deployments Need Action?
- On-premises N-central: Upgrade immediately to HF4. Direct upgrades are supported from 2025.4, 2026.1, 2026.2, 2026.3, and 2026.3 HF1–HF3. Older installations require an intermediate supported build.
- Hosted N-central (NCOD): N-able says server-side patches have already been applied, so customers do not need to install HF4 themselves.
- N-central agents: An agent upgrade is not required to close CVE-2026-86218 because the flaw is on the server. Keeping agents current remains a separate maintenance recommendation.
HF4 supersedes HF3, which superseded the earlier 2026.3 hotfixes. Administrators do not need to install each hotfix in sequence when their current build supports a direct move to 2026.3.1.14.
Why Is an N-central Compromise Especially Serious?
N-central is a privileged control plane used to administer many endpoints, often across multiple customer environments. A server compromise can therefore create a one-to-many attack path: access to the console may enable account changes, script execution, software deployment, or remote-control sessions on downstream systems.
That changes the remediation threshold. Updating the appliance stops the known entry points, but it does not reverse actions already taken through legitimate management features. Any organization that cannot rule out compromise should investigate the N-central server and the endpoints it managed during the exposure window.
What Should Defenders Do Now?
- Install and verify HF4. Upgrade on-premises servers to build 2026.3.1.14 and confirm the version running in production.
- Restrict console exposure. Place N-central behind a VPN or strict IP allowlist and remove unnecessary public access.
- Audit identities and permissions. Review newly created users, password resets, role changes, disabled security controls, and other unauthorized account activity.
- Review server activity. Examine available N-central logs for suspicious authentication events, unexpected administrative actions, configuration changes, and signs that logs were deleted or altered.
- Check downstream activity. Investigate unexplained Take Control sessions, scripts, jobs, software deployments, and unauthorized Cloudflare tunnel services on managed endpoints.
- Contain suspected compromise. Revoke sessions, rotate privileged credentials and integration secrets, remove unauthorized persistence, and validate managed endpoints before returning to normal operations.
How Can SOCRadar Support Prioritization?
SOCRadar Vulnerability Intelligence can help teams track changes in exploitation status and connect CVEs with vendor guidance, while External Attack Surface Management can identify exposed N-central services that require urgent review. Threat intelligence can also help analysts separate reusable indicators from the more durable behaviors associated with RMM abuse.
![]()
SOCRadar’s Vulnerability Intelligence
For this incident, version and exposure data should be combined with identity, API, remote-control, and endpoint telemetry. A patched server may still require investigation if it was reachable while an exploited vulnerability remained unfixed.
Conclusion
N-central 2026.3 HF4 is more than a patch for CVE-2026-86218: it is the current cumulative update after a rapid series of authentication and access control fixes. On-premises customers should move directly to build 2026.3.1.14, restrict access to the management console, and review activity from before the upgrade.
Because RMM compromise can extend to downstream systems, teams that cannot exclude prior access should investigate both the N-central server and the endpoints it controlled.

