• 3 min read
N-able confirms N-central zero-day reached customer networks
N-able confirms attackers used an N-central zero-day to reach customer networks and demands a second hotfix, even from customers who patched once.

Image: The Register
N-able says attackers exploited a critical zero-day in its N-central remote monitoring and management platform to reach customer networks, then issued a second mandatory hotfix only days after the first.
The vulnerability, CVE-2026-18577, allows an unauthenticated attacker to gain administrative access to vulnerable N-central servers. After compromising those servers, attackers used N-central’s Take Control feature to open remote-control sessions to systems inside customer environments.
N-able also confirmed that attackers created a new Cloudflare Tunnel service. That provided a persistent route into affected environments even after the attackers were removed from the N-central server, activity previously observed by Huntress.

Recommended reading
Ai+ commits Rs 100 crore to smartphone security
“This is not a duplicate of our previous communication. Hotfix 2 is required, even if you already applied the earlier hotfix.”
N-central Hotfix 2 replaces the first fix
N-able’s Hotfix 2, version 2026.3.1.10, applies to customers running N-central on-premises. The vendor says it must be installed immediately, including by organizations that installed the first emergency update, released on August 2. The new release supersedes Hotfix 1 and adds additional hardening as N-able monitors how attackers change their techniques.
The vendor has not said whether attackers bypassed Hotfix 1 or what specifically prompted the second round of defenses. Its current description says the vulnerable versions were those released before 2026.3.1.7, the version associated with the first hotfix. Hosted N-central environments have already received the latest mitigations.
N-able discovered the attacks on July 31, when its Adlumin managed detection and response service detected suspicious activity at a customer. Further investigation identified active exploitation of the zero-day. CISA then added CVE-2026-18577 to its Known Exploited Vulnerabilities catalog and gave US federal agencies until August 6 to remediate it—a three-day deadline indicating an urgent risk.
Limited disclosure leaves the impact unclear
N-central is valuable to attackers because managed service providers use it to administer large numbers of customer systems from one platform. Compromising the management server can therefore turn a single breach into access to downstream customer endpoints.
N-able says its investigation found that a “limited number” of customers were affected. It has not disclosed how many customers that represents, how many downstream systems attackers reached, or what they did after establishing persistence. The company also did not explain whether Hotfix 1 was circumvented.
The vendor has published 10 IP addresses associated with the attacks and released a service template for hunting known indicators of compromise on Windows endpoints. It cautions that a clean scan is not proof that an environment is safe: the tool checks only for indicators identified so far, and additional indicators may emerge.
The practical conclusion is unusually clear despite the incomplete disclosure: on-premises N-central operators must install Hotfix 2 even if Hotfix 1 is already installed, then investigate managed endpoints for the Cloudflare Tunnel and other indicators. The missing scope data prevents a reliable assessment of how widespread the intrusion became, but confirmed access into customer networks makes this more than a server-side patching exercise.
Security Editor
Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.
via The Register


