N-able N-central Hotfix 2 follows confirmed access to customer systems
N-able says attackers used its N-central flaw to reach managed endpoints, making Hotfix 2 mandatory for on-premises users.
By Renata Fuchs · Policy Reporter
· 3 min read
N-able has told customers that attackers exploiting its N-central vulnerability reached systems managed through the remote monitoring platform, while requiring on-premises users to install N-able N-central Hotfix 2, version 2026.3.1.10. The update is consequential for managed service providers because the compromise moved beyond the management server and into customer environments administered from it.
The vulnerability, CVE-2026-18577, is an authentication-bypass flaw that can give an unauthenticated attacker administrative control of an N-central console. N-central is used by MSPs to manage customer endpoints centrally, so console access can be used to run scripts, deploy tools or start remote-control sessions on downstream machines, according to Huntress.
N-able said attackers remotely exploited vulnerable N-central servers, then used its Take Control feature to connect to managed systems. The company’s investigation also found attackers registering a Cloudflare Tunnel service on those systems, giving them a means of retaining access after their N-central-server access had been removed, according to The Register.
The vendor said only a “limited number” of customers were affected. It has not disclosed the number of organizations or endpoints involved, what attackers did after establishing persistence, or an identity or objective for the operators. Those omissions leave the scale and eventual impact of the incident unresolved.
Which N-central deployments need Hotfix 2?
Organizations running N-central on premises must install Hotfix 2 immediately, even if they already deployed Hotfix 1, version 2026.3.1.7. N-able describes the new release as superseding the first update and adding hardening measures. It has not said that attackers bypassed Hotfix 1.
For hosted N-central environments, N-able says it has already applied the mitigations and customers do not need to take action. The affected version scope cited in later remediation guidance is N-central releases earlier than version 2026.3.1.7, followed by the new requirement to install version 2026.3.1.10 for on-premises deployments.
What should MSPs investigate after the N-central flaw?
The immediate operational task is broader than updating the RMM server. N-able’s account of the intrusion chain means potentially exposed operators should review both N-central activity and the managed endpoints reachable through it, including suspicious logins and Take Control sessions. Huntress has reported active exploitation targeting multiple organizations, though it said it had not observed a broad indiscriminate campaign across its partner base.
N-able has published 10 IP addresses associated with the attacks and a Windows endpoint service template for finding known indicators. The company cautioned that a clean result is not proof of no compromise because its indicator set may grow as the investigation continues. Readers can review Huntress’s technical update for its observed attacker activity and remediation guidance.
N-able first identified suspicious activity on July 31 through its Adlumin managed detection and response service. It issued Hotfix 1 on August 2. Huntress published active-exploitation findings on August 3, and N-able’s second hotfix was announced on August 6. CISA also placed CVE-2026-18577 in its Known Exploited Vulnerabilities catalog and set an August 6 remediation deadline for U.S. federal civilian agencies, according to The Register.
This story draws on original reporting from The Register.