N-able issued Hotfix 4 for N-central on September 6 to fix CVE-2026-86218, a pre-authentication remote code execution flaw in on-premises builds before 2026.3.1.14. That new build also supersedes Hotfix 3, so systems patched hours earlier still need this one.
The bug lets crafted input reach code paths the server treats as trusted, so an unauthenticated attacker can run code on the N-central box itself. N-able’s public notes say it has no production confirmation, while its customer notice and the Dutch NCSC both say exploit attempts were observed, which is why the advisory treats this as an immediate patching problem.
For MSP operators, the exposure is the management plane: a compromised N-central console can become a pivot into multiple customer environments, not just one server. On-premises instances carry that risk until they are on 2026.3.1.14; hosted NCOD customers were already patched, but the reporting still leaves the exploitation timeline contested.