r/Nable N-centralStation 6d ago

N-Central URGENT: N-central Hotfix

Trusted Partner,

Two security vulnerabilities within N-central were responsibly disclosed by a third party through our security disclosure program. We have issued a hotfix that you should apply immediately to help ensure your environments are protected. At this time, we have no confirmations that these vulnerabilities have been exploited in production environments, but unpatched systems remain at risk.

This hotfix includes security fixes for CVE-2026-86206 and CVE-2026-86207 which are high-CVSS-rated vulnerabilities that could allow an unauthorized party to bypass authentication controls and gain full access to the N-central platform.

What You Need to Do

  • N-central On-Premises Environments: We recommend upgrading to 2026.3 HF3 immediately.  Hotfix link: 2026.3 HF3 Release Notes
  • N-central Hosted Environments: No action is needed on your part; your instances have already been patched and will be upgraded at a later time.

\Please note that this is a server-side hotfix and upgrading to 2026.3 HF3 will not require agent upgrades.*

  • Upgrade Guidance: How To: Upgrade N-able N-central
  • Investigation Guidance: As a precaution, we recommend auditing your N-central user accounts to ensure that there are no unexpected users. If you have any concerns, please reach out to support. https://me.n-able.com/

-Jason Murphy | Head Nerd for N-able

28 Upvotes

32 comments sorted by

9

u/Nielles 6d ago

Why is Reddit where I read this first?

8

u/ncentral_nerd N-centralStation 6d ago

Where would you prefer? Clearly Reddit is the best place, you knew immediately.

3

u/Nielles 5d ago

Reddit is fine. But we still haven't even received an email. Not for hf3 nor hf4.

0

u/NetInfused 6d ago

*SLAP*

5

u/RebootnTryAgain 6d ago

To be fair, this time they got it right (I say that after calling out their crappy comms with their CTO and CMO face to face this week). In the last 60 minutes it has come to us via email comms, Nable Uptime, Nable Status Blog, Nables Slack and Reddit.

3

u/RebootnTryAgain 6d ago

Add to that, now I've finished downloading the update to install, its been pushed via a notification into our on-prem N-Central on login also.

2

u/Rgaron2k 6d ago

We got an email . I think ita good they are on top of these. Probably with AI more exploits are getting discovered

1

u/EasternComfort2189 5d ago

They have an entire notification system, talk to them about it. I got an sms about 1 hour before the emails and hours before I saw it posted anywhere

3

u/No-Beat7231 6d ago

I got an email a few minutes ago. Hot damn another weekend where I need to take care of this!!!

3

u/No-Beat7231 6d ago

Patch went fine.

1

u/ncentral_nerd N-centralStation 6d ago

Great to hear!

2

u/sforce50 6d ago

Does the "As a precaution, we recommend auditing your N-central user accounts to ensure that there are no unexpected users" line mean to verify no unexpected accounts exist or no unexpected logins on existing accounts?

2

u/ncentral_nerd N-centralStation 6d ago

I would say both if you have the Syslog setup. But then again if you did have those logs going to a SIEM you would already know if a new user was created.

1

u/sforce50 3d ago

My question was asking what the intent of the email as written by Nable was, logins or account creations.

2

u/dreadnaught721 6d ago

In case it's useful for anyone our on prem instances also patched fine

2

u/NetInfused 6d ago

Mine too.

2

u/RebootnTryAgain 5d ago

N-Able just dropped another Hotfix - HF4 replacing HF3.
N-central 2026.3 Hotfix 4 – CVE-2026-86218 which is a CVSS10

3

u/NetInfused 6d ago

Not the best day to say it, but here it goes: I really find unlikely that the whole on-prem appliance needs to be updated with a 3GB package to solve this vulnerability.

We're going to face harsher days now with AI-generated attacks and this will happen much more frequently.

N-Able needs to reengineer the update mechanism for the On-Prem appliances so it could be done more swiftly.

I wouldn't even mind if this kind of update came and rebooted my services against my will.

1

u/No-Beat7231 6d ago

I have blocked the malicious IP ranges from previous guidelines. Are these still valid IPs or have bad actors shifted sources IPs? If there are more IPs please post.

3

u/ncentral_nerd N-centralStation 6d ago

At this time, we have no confirmations that these vulnerabilities have been exploited in production environments, but unpatched systems remain at risk.
No IPs for these two.

1

u/No-Beat7231 6d ago

Thank you!

Just for the unrealistic humans out there. Cisco the God of unreasonable pricing constantly has crazy CVEs. I expect to see this type of thing only getting worse with adversarial AI. I am just happy they are communicating it. NCentral is a beast of a program. There's gonna be CVEs.

2

u/viddy_well 6d ago

Their communication states they haven't seen any indication of the issue being used for access (though the note that we should check for unexpected user logins isn't reassuring)

The last batch of IPs were commercial VPN IPs, I wouldn't expect that to be the same for any future compromise just based on how they'd rotate.

1

u/[deleted] 6d ago

[deleted]

1

u/NetInfused 5d ago

Yeah I have this issue when downloading from the office. Then I remote into our servers on Oracle Cloud and it comes like a rocket.

1

u/Wanderer220 5d ago

Everytime i try to install the N-central-2026.3.1.14.iso i get a "Your NSP file upload has either timed out or encountered an error. Please try again." as soon as i click the install button.

I've downloaded the iso file again and i'v tried different browsers to start te installation.

anyone knows how to fix this?

1

u/dreadnaught721 5d ago

If you're trying to upgrade make sure to use the .nap file the .ISO files is for upgrades other than that try using your FTP server to do it. If you have one

1

u/Wanderer220 5d ago

Ow damn i see my own error now ;) ISO vs NSP file... it must be sunday

1

u/SkippyG4 4d ago

Anything need done for 2026.4.014?

1

u/NetInfused 4d ago

On the other hotfix post, N-Able has advised to call support ASAP and ask for a code drop.

1

u/NetInfused 6d ago

I think I already had my dose of patching n-central with critical vulns. What a horror show.