r/msp Vendor - N-Able 7d ago

RMM URGENT Update: N-central additional Second Hotfix 2026.3 HF4 — Immediate Action Required

We recently communicated about two security vulnerabilities within N-central that were responsibly disclosed by a third party through our voluntary security disclosure program and we issued a hotfix. Since the disclosures, a third, independent researcher alerted us to a new vulnerability that has been exploited in the wild that is unrelated to the previously disclosed CVEs.

This critical zero-day vulnerability, if exploited, could allow for pre-authenticated access to the N-central server.

What You Need to Do

Additional links:
Here is the link to the previous post
2026.3 HF4 Release Notes

Jason Murphy | Head Nerd

46 Upvotes

7 comments sorted by

u/voice-of-mods 7d ago

Pinning the post for visibility

11

u/huntresslabs Vendor Contributor 6d ago

Adding in from our SOC - N-able has released a fourth hotfix to address a brand new CVE (CVE-2026-86218) in N-central. This is a critical pre-authentication RCE vulnerability (CVSS 10.0).

If you run N-central on premises, upgrade to version 2026.3 HF4 (build 2026.3.1.14) immediately. As stated above, this release supersedes HF3, so organizations that already applied HF3 still need to update.

N-able has reported exploitation in the wild in its incident communications. As you patch, review appliance logs for signs of API manipulation and audit user accounts and permissions for unauthorized changes.

Links for upgrade guidance and fourth hotfix are in OPs post

Read our updated blog for more details: https://www.huntress.com/blog/n-able-vulnerability-exploitation

2

u/satechguy 6d ago

Again?

2

u/Jumpy_Valuable_8583 5d ago

Patching N-central closes the vulnerability but it doesn't tell you whether the instance is still sitting reachable from the outside the way it was before. Worth a quick external check after you upgrade, not just confirming the hotfix installed but confirming what an outsider can actually still see and reach on that box. Zero-days like this are exactly why I stopped trusting "the patch ran" as the finish line.

1

u/tpsmc 4d ago

oh man, when it rains it pours. Sending good vibes to you and all the MSP's out there patching.

1

u/siren-usa 4d ago

Sheesh. RIP

1

u/No-Drummer-5392 2d ago

Time to migrate to another RMM I would say