September 05, 2026 - Started 1 day ago
- Lasted about 9 hours
Incident Report
Summary
AI Generated
Two security vulnerabilities (CVE-2026-86206 and CVE-2026-86207) were responsibly disclosed in N-able N-central, affecting both hosted and on-premises instances across Americas, Europe, and APAC regions. Mitigations were applied automatically to all hosted N-central environments, while on-premises customers are required to manually apply a hotfix immediately to remain protected. No confirmed exploitation in production environments was reported, but unpatched on-premises systems remain at risk.
Two security vulnerabilities within N-central were responsibly disclosed by a third party through our security disclosure program. We have issued a hotfix that you should apply immediately to help ensure your environments are protected. At this time, we have no confirmations that these vulnerabilities have been exploited in production environments, but unpatched systems remain at risk.
**N-able N-central Hosted Customers**: Mitigations were applied to all hosted N-central instances.
**N-central On-Premises Customers**: Download and upgrade using the instructions provided below and, on the N-able support portal. If you need assistance with the upgrade process, please contact our support team at https://me.n-able.com/s/
• Download links:
o Software Downloads: SD - 000134 (non-CMMC) - https://me.n-able.com/s/softwaredownloads/a9jVy0000000L2rIAE/sd-000134
o Software Downloads: SD - 000135 (CMMC) - https://me.n-able.com/s/softwaredownloads/a9jVy0000000L4TIAU/sd-000135
• Upgrading from legacy versions: https://documentation.n-able.com/N-central/userguide/Content/ReleaseDocs/Release_Notes/upgrade_path.htm
• Release Notes with download details is here: https://documentation.n-able.com/N-central/Release_Notes/GA/Content/N-central_2026.3_HF3_Release_Notes.htm
• CVE Details can be found here:
o CVE-2026-86206 - https://www.cve.org/CVERecord?id=CVE-2026-86206
o CVE-2026-86207 - https://www.cve.org/CVERecord?id=CVE-2026-86207
As a precaution, we recommend auditing your N-central user accounts to ensure that there are no unexpected users. If you have any concerns, please reach out to support - https://me.n-able.com/.
The Status Page Aggregator with Early Outage Detection
With IsDown, you can monitor all your critical services' official status pages from one centralized dashboard and receive instant alerts the moment an outage is detected. Say goodbye to constantly checking multiple sites for updates and stay ahead of outages with IsDown.