N-Able Patches a Flaw in the Software IT Providers Use to Reach Client Machines

N-able has shipped an emergency update for N-central, the software IT providers use to manage their customers' computers from a single console. The update, N-central 2026.3 Hotfix 4, was posted on Sept. 6 and closes a flaw that could let someone run code on an N-central server without first logging in.
N-able sells N-central to managed service providers and in-house IT teams as remote monitoring and management software, so one N-central server reaches machines across many customers' networks.
N-able's advisory identifies the flaw as CVE-2026-86218 and describes it as a critical, CVSS-rated vulnerability allowing pre-authenticated remote code execution on the N-central server; it gives no score. The advisory says a third party reported the flaw through the company's security disclosure program, and that N-able has no confirmation the flaw has been exploited in production environments, though unpatched systems remain at risk.
Customers running N-central on their own hardware should upgrade to build 2026.3.1.14 immediately, N-able says. Instances the company hosts itself have already been patched and need no action. The advisory adds that the agent software on managed machines does not have to be upgraded for the hotfix to protect against this flaw. It lists direct upgrade paths to that build from 2025.4 onward.
Hotfix 4 supersedes N-central 2026.3 Hotfix 3, build 2026.3.1.13.
