Close Menu
NCIJ Network NCIJ Network
    What's Hot

    What does Mondlane’s trial mean for Mozambique? | News

    September 8, 2026

    Merz has no good answers as the far right targets his downfall – POLITICO

    September 8, 2026

    Astronomers Have Completed the Largest Map of Space. Yes, You Can Play With It.

    September 8, 2026
    Facebook X (Twitter) Instagram
    Trending
    • What does Mondlane’s trial mean for Mozambique? | News
    • Merz has no good answers as the far right targets his downfall – POLITICO
    • Astronomers Have Completed the Largest Map of Space. Yes, You Can Play With It.
    • N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw
    • A seven-year-old blockchain is permanently abandoning its own network to seek refuge on Ethereum
    • Ukraine’s chief prosecutor resigns over call centre corruption scandal
    • AI cancer cures slowed by chip shortage, says UK’s biggest tech boss
    • Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, September 8
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 8, 2026 Cybersecurity No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Every on-premises N-central build below 2026.3.1.14 — including servers updated to Hotfix 3 a day earlier — needs Hotfix 4. N-able’s incident notice says the flaw has been exploited in the wild; its release notes say that is unconfirmed.

    N-able has released its fourth hotfix in five weeks for the N-central remote monitoring and management (RMM) platform, this time for a maximum-severity vulnerability that could allow remote code execution on the N-central server without authentication.

    The company’s own communications disagree on whether the flaw has already been exploited.

    The vulnerability, tracked as CVE-2026-86218, carries a CVSS 4.0 score of 10.0, assigned by N-able as the CVE Numbering Authority, and is classed as a static code injection weakness (CWE-96).

    It affects every N-central build before 2026.3.1.14, the build shipped as 2026.3 Hotfix 4 in the early hours of September 6 (UTC). That includes servers already updated to Hotfix 3 (2026.3.1.13), which N-able had published a little over eight hours earlier for two flaws that it says are unrelated to the new one.

    Cybersecurity

    N-able said hosted N-central (NCOD) instances have already been patched. On-premises customers are told to upgrade to 2026.3.1.14 immediately; the release notes list direct upgrade paths from 2025.4, 2026.1, 2026.2, 2026.3, and the 2026.3.1 hotfixes, and say agents do not need to be upgraded to be protected from this CVE.

    The release notes, status post, and incident notice contain no indicators of compromise, no interim mitigation, and no detection guidance beyond a recommendation to audit N-central user accounts for unexpected users.

    Huntress, which has been tracking attacks on N-central since August, has advised administrators to restrict inbound access to the console with IP allowlisting or a VPN and, where a server is still reachable from the internet, to consider taking it offline until the hotfix is applied.

    On the question of exploitation, N-able’s channels diverge. The Hotfix 4 release notes and status post state that a third party responsibly disclosed the vulnerability through the company’s security disclosure program and that N-able has “no confirmations that this vulnerability has been exploited in production environments.”

    The same release notes on N-able’s documentation site also describe it as a “critical zero-day vulnerability,” a term N-able does not define.

    N-able’s incident notice on its uptime status page goes further. It says a third, independent security researcher alerted the company to a new vulnerability unrelated to the previously disclosed CVEs and that, unlike those, the newly identified flaw “has been observed being exploited in the wild.”

    The notice does not say who observed the exploitation, where, or when, and N-able has not attributed the activity to any actor. As of September 7, the incident was still listed as open on N-able’s status page, as mirrored by the status-page aggregator IsDown.

    The Hacker News has reached out to N-able for clarification on which statement is current and what evidence of exploitation the company holds.

    Huntress said it cannot settle the question from its own data. The company began investigating on September 4 after a customer’s fully patched N-central production environment was compromised. It said it reproduced a proof-of-concept exploit chain against build 2026.3.1.10 that may use one or both of the two flaws later fixed in Hotfix 3, but the appliance’s logs had already rotated, leaving it “unable to say whether this new CVE was the vulnerability exploited” in that intrusion.

    The hotfix is the fourth N-able has issued for the 2026.3 line since August 2 and covers the third distinct set of vulnerabilities:

    • Hotfix 1 (2026.3.1.7), August 2 — CVE-2026-18577, an incomplete fix for CVE-2026-18556 that still allowed authentication bypass and account takeover; exploited in the wild
    • Hotfix 2 (2026.3.1.10), August 6 — additional hardening for a related attack path
    • Hotfix 3 (2026.3.1.13), September 5 — CVE-2026-86206, unauthorized access to internal APIs through the access control filter, and CVE-2026-86207, an authentication bypass in internal-only APIs
    • Hotfix 4 (2026.3.1.14), September 6 — CVE-2026-86218, pre-authentication remote code execution

    N-able described the two Hotfix 3 flaws as “high-CVSS-rated” vulnerabilities that could allow an unauthorized party to bypass authentication controls and gain full access to the platform.

    Its own CVE records score CVE-2026-86207 at 7.7 (High) and CVE-2026-86206 at 6.9 (Medium). The company said it had no confirmation that either had been exploited in production environments.

    Cybersecurity

    The August hotfixes followed an intrusion N-able said it detected on July 31. Attackers used the authentication bypass to obtain administrative access to N-central servers, then used the platform’s Take Control feature to reach managed endpoints and register Cloudflare tunnel services on those devices, maintaining access after the route through N-central was cut off.

    N-able said a limited number of customers were affected, its first fix proved incomplete, and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added both CVEs to its Known Exploited Vulnerabilities catalog. On August 10, the company said a full root-cause analysis was coming.

    It is the second summer in a row that N-central has drawn in-the-wild attacks: in August 2025, two other flaws in the product, CVE-2025-8875 and CVE-2025-8876, were added to CISA’s catalog the same day N-able released fixes for them.

    Flaw fourth Hotfix issues Nable Ncentral RCE unauthenticated weeks
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released

    ⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More

    PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution

    Hackers exploit new MikroTik RouterOS flaws to hijack routers

    North Korean Hackers Deploy New Linux Espionage Toolkit

    Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    What does Mondlane’s trial mean for Mozambique? | News

    September 8, 2026

    Merz has no good answers as the far right targets his downfall – POLITICO

    September 8, 2026

    Astronomers Have Completed the Largest Map of Space. Yes, You Can Play With It.

    September 8, 2026

    N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw

    September 8, 2026
    Latest Posts

    Book Review: ‘Pure Men’ by Mohamed Mbougar Sarr

    August 1, 2026

    Bitcoin ETFs Post First Monthly Inflow Since April

    August 1, 2026

    Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

    August 1, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    What does Mondlane’s trial mean for Mozambique? | News

    September 8, 2026

    Merz has no good answers as the far right targets his downfall – POLITICO

    September 8, 2026

    Astronomers Have Completed the Largest Map of Space. Yes, You Can Play With It.

    September 8, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.