Current answer
N-able experienced a minor incident: URGENT: N-CENTRAL IMMEDIATE HOTFIX REQUIRED. The provider currently marks this incident Identified.
Looking for an update now? Check the current status, or follow N-able for future changes.
Incident Lifecycle
Affected Components
N-central (hosted version) (Americas)
N-central (hosted version) (APAC)
N-central (hosted version) (Europe)
N-central On-premise (Americas)
N-central On-premise (APAC)
N-central On-premise (Europe)
Incident Timeline
Identified
**URGENT: N-CENTRAL IMMEDIATE HOTFIX REQUIRED**
We recently communicated about two security vulnerabilities within N-central that were responsibly disclosed by a third party through our voluntary security disclosure program (https://uptime.n-able.com/event/201813/). To address these issues, we released a hotfix and strongly recommend that it be applied immediately to help ensure your environment remains protected. At the time of our initial communication, we had no confirmed evidence that either vulnerability had been exploited in production environments, though unpatched systems remained at risk.
Since those disclosures, **a third, independent security researcher has alerted us to a new separate vulnerability that is unrelated to the previously disclosed CVEs.** Unlike the earlier vulnerabilities, this newly identified vulnerability has been observed being exploited in the wild. We are actively investigating this matter and have taken additional steps to help protect customer environments.
**N-able N-central Hosted Customers:** Mitigations were applied to all hosted N-central instances.
**N-central On-Premises Customers:** Download and upgrade using the instructions provided below and, on the N-able support portal. If you need assistance with the upgrade process, please contact our support team at **https://me.n-able.com/s/**
* 2026.3 HF4 Download links:
* Non CMMC: **[Software Downloads: SD - 000136](https://me.n-able.com/s/softwaredownloads/a9jVy0000000L65IAE/sd-00013)**
* CMMC : **[Software Downloads: SD - 000137](https://me.n-able.com/s/softwaredownloads/a9jVy0000000L7hIAE/sd-000137)**
If you’ve already upgraded to 2026.3 HF3, you will need to upgrade to 2026.3 HF4 to protect against this newly discovered vulnerability.
* Upgrade Documentation: **https://me.n-able.com/s/article/How-To-Upgrade-N-able-N-central**
* Upgrading from legacy versions: **https://documentation.n-able.com/N-central/userguide/Content/ReleaseDocs/Release_Notes/upgrade_path.htm**
* 2026.3 HF4 Release Notes: **https://documentation.n-able.com/N-central/Release_Notes/GA/Content/N-central_2026.3_HF4_Release_Notes.htm**
* CVE Details can be found here: **[CVE-2026-86206](https://www.cve.org/CVERecord?id=CVE-2026-86206)** , **[CVE-2026-86207](https://www.cve.org/CVERecord?id=CVE-2026-86207)** , and **[CVE-2026-86218](https://www.cve.org/CVERecord?id=CVE-2026-86218)**
As this is a critical zero-day vulnerability, we need you to apply this hotfix immediately to protect you and your customers. As a precaution, we recommend auditing your N-central user accounts to ensure that there are no unexpected users.
If you have any concerns, please reach out to support.** https://me.n-able.com/**
We recently communicated about two security vulnerabilities within N-central that were responsibly disclosed by a third party through our voluntary security disclosure program (https://uptime.n-able.com/event/201813/). To address these issues, we released a hotfix and strongly recommend that it be applied immediately to help ensure your environment remains protected. At the time of our initial communication, we had no confirmed evidence that either vulnerability had been exploited in production environments, though unpatched systems remained at risk.
Since those disclosures, **a third, independent security researcher has alerted us to a new separate vulnerability that is unrelated to the previously disclosed CVEs.** Unlike the earlier vulnerabilities, this newly identified vulnerability has been observed being exploited in the wild. We are actively investigating this matter and have taken additional steps to help protect customer environments.
**N-able N-central Hosted Customers:** Mitigations were applied to all hosted N-central instances.
**N-central On-Premises Customers:** Download and upgrade using the instructions provided below and, on the N-able support portal. If you need assistance with the upgrade process, please contact our support team at **https://me.n-able.com/s/**
* 2026.3 HF4 Download links:
* Non CMMC: **[Software Downloads: SD - 000136](https://me.n-able.com/s/softwaredownloads/a9jVy0000000L65IAE/sd-00013)**
* CMMC : **[Software Downloads: SD - 000137](https://me.n-able.com/s/softwaredownloads/a9jVy0000000L7hIAE/sd-000137)**
If you’ve already upgraded to 2026.3 HF3, you will need to upgrade to 2026.3 HF4 to protect against this newly discovered vulnerability.
* Upgrade Documentation: **https://me.n-able.com/s/article/How-To-Upgrade-N-able-N-central**
* Upgrading from legacy versions: **https://documentation.n-able.com/N-central/userguide/Content/ReleaseDocs/Release_Notes/upgrade_path.htm**
* 2026.3 HF4 Release Notes: **https://documentation.n-able.com/N-central/Release_Notes/GA/Content/N-central_2026.3_HF4_Release_Notes.htm**
* CVE Details can be found here: **[CVE-2026-86206](https://www.cve.org/CVERecord?id=CVE-2026-86206)** , **[CVE-2026-86207](https://www.cve.org/CVERecord?id=CVE-2026-86207)** , and **[CVE-2026-86218](https://www.cve.org/CVERecord?id=CVE-2026-86218)**
As this is a critical zero-day vulnerability, we need you to apply this hotfix immediately to protect you and your customers. As a precaution, we recommend auditing your N-central user accounts to ensure that there are no unexpected users.
If you have any concerns, please reach out to support.** https://me.n-able.com/**
Sep 6, 2026 at 4:15 AM UTC
Was your business affected by this N-able outage?
Follow N-able and route available status alerts to email or a team channel.