# Urgent Patch Released for Critical Vulnerability in N-central Platform

*Published September 9, 2026*
*Source: [https://www.securityweek.com/n-able-patches-critical-zero-day-in-n-central/](https://www.securityweek.com/n-able-patches-critical-zero-day-in-n-central/)*

## Executive Summary

N-able has released a critical patch for a zero-day vulnerability in its N-central platform that allows unauthorized access. On-premises users must apply the hotfix immediately to protect their systems from potential exploitation.

## Article

N-able, a prominent IT software company, has released a critical fix for a remote code execution vulnerability in its N-central endpoint management platform. This security flaw, identified as CVE-2026-86218, carries the highest possible severity rating with a CVSS score of 10 out of 10. The vulnerability allows unauthorized users to gain access to N-central servers, posing significant risks to the affected systems. N-able discovered this issue following the patching of two other vulnerabilities in N-central, namely CVE-2026-86206 and CVE-2026-86207. While N-central's hosted environments have already received the necessary patches server-side, users who run on-premises instances of N-central must urgently apply the 2026.3 HF4 hotfix to secure their systems. N-able also advises administrators to examine their logs for any suspicious scanning activities, particularly those originating from the IP range 23.234.64.0/18, which may indicate attempts to exploit this vulnerability. Additionally, administrators should inspect their deployments for any unfamiliar user accounts. Although there have been no confirmed cases of this vulnerability being exploited in production environments, systems that remain unpatched are still at risk. The latest hotfix addresses the zero-day vulnerability and replaces previously issued patches for the related bugs. However, due to limitations in historical logging, it remains unclear which specific exploit was used by threat actors to compromise N-central environments. Huntress, a cybersecurity firm, reported observing attacks on N-central's API and appliance logs since September 4, 2026, highlighting the need for vigilance and prompt action.
