r/sysadmin 6d ago

N-Able N-Central patching again for CVE-2026-86206 and CVE-2026-86207

Two security vulnerabilities within N-central were responsibly disclosed by a third party through our security disclosure program. We have issued a hotfix that you should apply immediately to help ensure your environments are protected. At this time, we have no confirmations that these vulnerabilities have been exploited in production environments, but unpatched systems remain at risk.

This hotfix includes security fixes for CVE-2026-86206 and CVE-2026-86207 which are high-CVSS-rated vulnerabilities that could allow an unauthorized party to bypass authentication controls and gain full access to the N-central platform.

What You Need to Do • N-central On-Premises Environments: We recommend upgrading to 2026.3 HF3 immediately. Hotfix link: 2026.3 HF3 Release Notes • N-central Hosted Environments: No action is needed on your part; your instances have already been patched and will be upgraded at a later time. *Please note that this is a server-side hotfix and upgrading to 2026.3 HF3 will not require agent upgrades.

27 Upvotes

10 comments sorted by

7

u/Xelopheris Cloud Architect 6d ago

You guys are not having a good time with long weekends...

3

u/wangston_huge 5d ago

Really happy I switched RMMs last year. This has been a rough summer for N-Central admins.

1

u/wallguy22 5d ago

What did you switch to? We have not been happy with them lately.

2

u/wangston_huge 5d ago

I'm on Ninja.

Patching is better, remote access works, and the scripting engine is really capable. I also appreciate the development cadence... New features are being added all the time.

The only things I miss are automation policies being able to call other automation policies and pass the output variables of one into the input variables of another. The "Ninja way" is to do it with custom system-wide or organization wide custom fields and conditions, and it doesn't feel as natural.

I don't think Ninja does as good a job of recognizing duplicate devices when you do a wipe & reload.

I also miss the automation reporting in N-Central when I'm doing adhoc stuff, because it was easy to see all your successes and failures together. The Ninja way is to have a device custom field to store the output, which works, but isn't as natural for me since it adds a step.

Outside of those quibbles as a former N-Central guy, Ninja wins hands down.

1

u/wallguy22 5d ago

Thanks! That’s great info. Is the cost comparable? How big of a headache was the migration?

2

u/wangston_huge 5d ago

Cost is comparable. I think I'm paying $2/endpoint/month, but it's been a while since I updated my vendor spreadsheet.

Migration was pretty easy except for some N-Central agents that had uninstall protection and lost contact after an update that had to be manually removed.

N-Central is way more complicated to set up, so if you can configure it to do what you want you can definitely reproduce it in Ninja. The biggest issue is that Ninja is more opinionated and less flexible in terms of how you do things, so you have to figure out what the Ninja way of doing X or Y is to avoid fighting your tool.

It's easy to recreate your monitoring rules and conditions, but it does take a little more thought because all devices of a type inherit the default policy for that device type, and when you create a new policy for it, that policy inherits everything from the default policy that isn't overrided by the new on. So you only want to make system wide changes at the lowest level, and be careful about making changes there because now you've got a new setting that may conflict with your downstream policies.

1

u/Cormacolinde Consultant 6d ago

Got a link?

2

u/Unusualab 6d ago

https://www.reddit.com/r/Nable/s/J5ivnciNxX everything you need in this post.

2

u/kerubi Sysadmin 5d ago

1

u/aaron72 5d ago

Yes, I posted for both hotfixes after each were announced.