N-able has introduced a new hotfix for its N-central platform in response to ongoing security threats exploiting a vulnerability in their Remote Monitoring and Management (RMM) system. This release aims to bolster defenses against evolving cyber attack strategies.
Proactive Security Measures
The company has emphasized the necessity of deploying Hotfix 2, even for those who have previously installed the initial update. This latest fix builds upon previous efforts by integrating additional security measures to protect both service providers and their clients effectively.
On July 31, 2026, N-able identified unusual activity within a client’s system, leading to the discovery of a zero-day vulnerability in the N-central server, designated as CVE-2026-18577. This vulnerability, which affects all versions before 2026.3.1.7, allows attackers to bypass authentication and take over accounts.
Impact and Exploitation Details
The identified vulnerability was initially linked to an attempt to rectify a prior flaw, CVE-2026-18556. Both issues have been highlighted by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) as actively being exploited. Attackers have used these vulnerabilities to gain remote administrative access, leveraging the Take Control feature to infiltrate systems managed by N-central.
After gaining entry, threat actors established a new service using a Cloudflare Tunnel, ensuring persistent access even if their initial entry point was closed. N-able has confirmed that only a small number of customers have been directly impacted by these incidents.
Recommended Actions for Users
Users operating on-premise versions of the affected software are urged to upgrade to version 026.3.1.10 immediately. To assist in identifying potential security breaches, N-able has also provided a list of IP addresses associated with these attacks as indicators of compromise (IoCs).
Furthermore, a custom service template has been made available to help customers automate the process of checking Windows device endpoints for known IoCs within the N-central environment. While a clean scan does not guarantee security, it serves as a vital component of a comprehensive security assessment.
The company stresses the importance of conducting a thorough review of system logs and account activities as part of an ongoing security protocol. As investigations continue, additional indicators may emerge, requiring further vigilance and proactive measures.
