Summary
N-able released a critical hotfix for N-central to fix a CVSS 10.0 unauthenticated remote code execution vulnerability (CVE-2026-86218) that may be under active exploitation. The update is the fourth in five weeks and affects all on-premises builds prior to 2026.3.1.14.
Take Action:
If you run N-central on-premises, upgrade to build 2026.3.1.14 (Hotfix 4) ASAP. Earlier builds, including Hotfix 3 released just hours before, are still vulnerable to unauthenticated remote code execution. Until the hotfix is applied, take any internet-facing console offline or restrict it to a VPN/IP allowlist. Assume that a compromised server means every managed endpoint behind it needs checking too.
Read the full article on BeyondMachines
This article was originally published on BeyondMachines
Top comments (0)