N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw
N-able has released Hotfix 4 for the N-central Remote Monitoring and Management platform to address a critical, pre-authentication remote code execution vulnerability identified as CVE-2026-86218. This flaw, which carries a CVSS score of 10.0 and allows unauthenticated attackers to execute arbitrary code on the server, has reportedly been actively exploited in the wild according to N-able's incident notice, although the company's official release notes currently state that such exploitation remains unconfirmed.
This update is particularly urgent because it supersedes Hotfix 3, meaning systems patched just one day prior to this release remain vulnerable. All on-premises installations running builds older than 2026.3.1.14 must be updated immediately to prevent unauthorized access and potential endpoint compromise. N-able advises administrators to restrict network exposure and audit user accounts while waiting for deployment completion, noting that hosted instances have already been secured.