N-able N-central contains a static code injection vulnerability that could allow for pre-authentication remote code execution.
An authentication bypass in N-central < 2026.3 HF 3 leads to authentication bypass in internal only APIs
A vulnerability in the N-central internal API access control filter allows unauthorised access to internal APIs. This is fixed in N-central 2026.3 HF3 and 2026.4
Two security vulnerabilities within N-central were responsibly disclosed by a third party through our security disclosure program. We have issued a hotfix that you should apply immediately to help ensure your environments are protected. At this time, we have no confirmations that these vulnerabilities have been exploited in production environments, but unpatched systems remain at risk.
This hotfix includes security fixes for CVE-2026-86206 and CVE-2026-86207 which are high-CVSS-rated vulnerabilities that could allow an unauthorized party to bypass authentication controls and gain full access to the N-central platform.
What You Need to Do • N-central On-Premises Environments: We recommend upgrading to 2026.3 HF3 immediately. Hotfix link: 2026.3 HF3 Release Notes • N-central Hosted Environments: No action is needed on your part; your instances have already been patched and will be upgraded at a later time. Please note that this is a server-side hotfix and upgrading to 2026.3 HF3 will not require agent upgrades.
Orgs have already been ransomwared, patch immediately
Copied from r/msp
As our investigation into the recent N-central security vulnerability continues, we are proactively expanding protections in response to ongoing monitoring of threat actors as they evolve their attack techniques.
This is not a duplicate of our previous communication. Hotfix 2 is required, even if you already applied the earlier hotfix. Hotfix 2 supersedes Hotfix 1 with additional hardening measures to further protect you and your customers.
What You Need to Do:
N-central On-Premises Environments: You must upgrade to 2026.3.1.10 immediately. Download here: https://status.n-able.com/2026/08/06/n-central-2026-3-hotfix-2-additional-mitigation-for-cve-2026-18577
N-central Hosted Environments: No action is required. We have already applied mitigations to your environment.
For More Information:
· Blog: https://www.n-able.com/blog/n-central-security-update-august-6-2026
· Support: https://me.n-able.com/s/
· CVE: https://www.cve.org/CVERecord?id=CVE-2026-18577
· Uptime: https://uptime.n-able.com/
Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass.
This issue affects N-central: through 2026.1.
An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1
Improper Input Validation vulnerability in N-able N-central allows OS Command Injection.This issue affects N-central: before 2025.3.1.
Deserialization of Untrusted Data vulnerability in N-able N-central allows Local Execution of Code.This issue affects N-central: before 2025.3.1.
The N-central server is vulnerable to session rebinding of already authenticated users when using Entra SSO, which can lead to authentication bypass. This vulnerability is present in all Entra-supported deployments of N-central prior to 2024.3.
An Incorrect File Handling Permission bug exists on the N-central Windows Agent and Probe that, in the right circumstances, can allow a local low-level user to run commands with elevated permissions.
On N-central, it is possible for any authenticated user to read, write and modify syslog configuration across customers on an N-central server. This vulnerability is present in all deployments of N-central prior to 2025.2.
The N-central Software Probe < 2025.4 is vulnerable to Remote Code Execution via deserialization
N-central versions < 2025.4 are vulnerable to multiple XML External Entities injection leading to information disclosure
N-central < 2025.4 can generate sessionIDs for unauthenticated users
This issue affects N-central: before 2025.4.