N-able’s public channels cannot agree on whether attackers are exploiting the newest N-central flaw, even as the company ships its fourth hotfix in five weeks. The release notes call the bug responsibly disclosed with no confirmed exploitation; a customer notice marked urgent calls it a zero-day observed in the wild.
The fix, Hotfix 4 (2026.3.1.14), landed in the early hours of September 6 for CVE-2026-86218, a CWE-96 static code injection flaw rated 10.0 under CVSS 4.0 that allows pre-authentication code execution on the N-central server. Every older on-premises build is affected, including Hotfix 3 (2026.3.1.13), shipped about eight hours earlier to cover CVE-2026-86206 and CVE-2026-86207, an access-control gap and an authentication bypass that together open the whole platform. Hosted instances are already patched, and agents need no update.
The public status post says a third party reported the vulnerability through the disclosure program and there is no confirmation it was exploited in production. N-able’s incident notice instead says the flaw has been observed exploited in the wild, spans hosted and on-premises N-central in the Americas, APAC, and Europe, and was still listed as open on September 7.
Huntress, which has followed the N-central saga since August, began digging on September 4 after a customer’s fully patched server was compromised. Its test chain worked against the 2026.3.1.10 build and likely leans on the Hotfix 3 bugs, but the compromised appliance had already purged its logs, leaving the responsible CVE unconfirmed for that incident.
On-premises operators should move to 2026.3.1.14 now and audit N-central accounts for unexpected users. Huntress adds IP allowlisting or VPN-only console access, and suggests taking internet-reachable servers offline until the hotfix is applied.
