# N-able issues hotfix for N-central zero-day

_Tuesday, September 8, 2026 at 6:37 AM EDT · Security · Latest · Tier 1 — Major_

![N-able issues hotfix for N-central zero-day — Primary](https://www.securityweek.com/wp-content/uploads/2026/02/API-security-risks.jpeg)

N-able released an urgent hotfix for CVE-2026-86218, a critical unauthenticated remote-code-execution vulnerability in its N-central endpoint-management platform. The company said the flaw had been exploited as a zero-day and that on-premises users should apply the 2026.3 HF4 hotfix; hosted environments received server-side patches.

Huntress observed attacks targeting N-central's API and appliance logs beginning September 4. Administrators were also advised to review logs for scanning activity and check for unfamiliar user accounts. The hotfix supersedes patches for two earlier N-central flaws.

## Sources

- [SecurityWeek](https://www.securityweek.com/n-able-patches-critical-zero-day-in-n-central/)

---
Canonical: https://techandbusiness.org/newswire/09OVsFAC4fzuDauetKMVT9
Retrieved: 2026-09-08T13:18:57.597Z
Publisher: Tech & Business (techandbusiness.org)
