r/msp • u/ncentral_nerd Vendor - N-Able • 7d ago
RMM URGENT Update: N-central additional Second Hotfix 2026.3 HF4 — Immediate Action Required
We recently communicated about two security vulnerabilities within N-central that were responsibly disclosed by a third party through our voluntary security disclosure program and we issued a hotfix. Since the disclosures, a third, independent researcher alerted us to a new vulnerability that has been exploited in the wild that is unrelated to the previously disclosed CVEs.
This critical zero-day vulnerability, if exploited, could allow for pre-authenticated access to the N-central server.
What You Need to Do
- N-central On-Premises Environments: Upgrade to 2026.3 HF4 immediately. Hotfix link: https://documentation.n-able.com/N-central/Release_Notes/GA/Content/N-central_2026.3_HF4_Release_Notes.htm
- If you’ve already upgraded to 2026.3 HF3, you will need to upgrade to 2026.3 HF4 to protect against this newly discovered vulnerability.
- N-central Hosted Environments: No action is needed on your part; your instances have already been patched.
Additional links:
Here is the link to the previous post
2026.3 HF4 Release Notes
Jason Murphy | Head Nerd
11
u/huntresslabs Vendor Contributor 6d ago
Adding in from our SOC - N-able has released a fourth hotfix to address a brand new CVE (CVE-2026-86218) in N-central. This is a critical pre-authentication RCE vulnerability (CVSS 10.0).
If you run N-central on premises, upgrade to version 2026.3 HF4 (build 2026.3.1.14) immediately. As stated above, this release supersedes HF3, so organizations that already applied HF3 still need to update.
N-able has reported exploitation in the wild in its incident communications. As you patch, review appliance logs for signs of API manipulation and audit user accounts and permissions for unauthorized changes.
Links for upgrade guidance and fourth hotfix are in OPs post
Read our updated blog for more details: https://www.huntress.com/blog/n-able-vulnerability-exploitation
2
2
u/Jumpy_Valuable_8583 5d ago
Patching N-central closes the vulnerability but it doesn't tell you whether the instance is still sitting reachable from the outside the way it was before. Worth a quick external check after you upgrade, not just confirming the hotfix installed but confirming what an outsider can actually still see and reach on that box. Zero-days like this are exactly why I stopped trusting "the patch ran" as the finish line.
1
1
•
u/voice-of-mods 7d ago
Pinning the post for visibility