DEV Community

Cover image for N-able Issues Emergency Hotfix for Maximum-Severity Unauthenticated RCE in N-central
BeyondMachines for BeyondMachines

Posted on Originally published at beyondmachines.net

N-able Issues Emergency Hotfix for Maximum-Severity Unauthenticated RCE in N-central

Summary

N-able released a critical hotfix for N-central to fix a CVSS 10.0 unauthenticated remote code execution vulnerability (CVE-2026-86218) that may be under active exploitation. The update is the fourth in five weeks and affects all on-premises builds prior to 2026.3.1.14.

Take Action:

If you run N-central on-premises, upgrade to build 2026.3.1.14 (Hotfix 4) ASAP. Earlier builds, including Hotfix 3 released just hours before, are still vulnerable to unauthenticated remote code execution. Until the hotfix is applied, take any internet-facing console offline or restrict it to a VPN/IP allowlist. Assume that a compromised server means every managed endpoint behind it needs checking too.


Read the full article on BeyondMachines


This article was originally published on BeyondMachines

Top comments (0)