VMTech
Discuss a project

N-able releases Hotfix 2 for actively exploited N-central flaw

N-able releases Hotfix 2 for actively exploited N-central flaw

N-able has released Hotfix 2 for its N-central remote monitoring and management platform while investigating ongoing exploitation of CVE-2026-18577, a vulnerability with a CVSS score of 8.2. The company said the update is mandatory even for customers that applied the earlier Hotfix 1, because Hotfix 2 supersedes it with additional hardening measures.

N-able detected unusual activity in a customer environment on July 31, 2026. Its investigation identified unknown threat actors exploiting the then-zero-day flaw in N-central servers. The company said a limited number of customers have been affected.

Attackers moved from N-central to managed devices

CVE-2026-18577 affects N-central versions before 2026.3.1.7. It is an incomplete fix for CVE-2026-18556, also rated 8.2. Both flaws can enable authentication bypass and account takeover in susceptible versions, and the U.S. Cybersecurity and Infrastructure Security Agency has flagged both as actively exploited.

In the activity observed by N-able, attackers obtained remote administrative access to the N-central server. They then used the platform’s Take Control feature to connect to devices in the N-central managed environment. After reaching those systems, the actors registered a new Cloudflare Tunnel service, creating a persistence mechanism that could remain available after access to the N-central server had been removed.

Hotfixing must be paired with investigation

N-able advised customers running on-premise N-central to update immediately to version 2026.3.1.10. The vendor also published an expanded list of IP addresses as indicators of compromise and released a custom service template for checking Windows device endpoints against known indicators from within N-central.

The automated check is not intended to establish that an environment is clean. N-able said its investigation remains ongoing and that additional indicators may emerge. It recommends combining the template with a thorough review of the environment, logs and account activity.

The incident reinforces a theme in Cisco flaws, ClickFix chains and AI agent incidents about Cisco vulnerabilities, ClickFix chains and rising incidents involving AI agents: trusted administrative tooling can become a high-impact route into enterprise systems when attackers obtain privileged access.

Business implication

Organizations using on-premise N-central should deploy version 2026.3.1.10, check managed Windows endpoints for the published indicators, and investigate remote-control activity, new services and privileged-account events so that remediation addresses both the server flaw and possible persistence on managed devices.

#cybersecurity#vulnerability#rmmsecurity#incidentresponse
Open analytics
On the site 0 views
min read 3 08.08.2026
Instagram

N-able releases Hotfix 2 for actively exploited N-central flaw

Open the post on Instagram ↗