N-able has issued a new set of hotfixes for its N-central Remote Monitoring and Management product following the discovery of a security flaw actively exploited by attackers. This latest update, labeled Hotfix 2, is designed to address vulnerabilities that have allowed threat actors to gain persistent access to managed systems. The company emphasized that Hotfix 2 introduces additional hardening measures beyond those provided in the previous update and is necessary even for those who have applied Hotfix 1. This move follows N-able's identification of unusual activity in a customer's environment on July 31, 2026, which led to the discovery of attackers exploiting a zero-day vulnerability, cataloged as CVE-2026-18577, with a high CVSS score of 8.2. This vulnerability, along with another known as CVE-2026-18556, allows attackers to bypass authentication and take over accounts in affected versions of the product. These vulnerabilities have been flagged as actively exploited by the U.S. Cybersecurity and Infrastructure Security Agency. Attackers have been observed using the flaw to gain administrative access, leveraging the Take Control feature to connect to systems within the N-central managed environment. Once inside, they established a Cloudflare Tunnel service to maintain persistence. N-able has confirmed that a limited number of customers have been affected. Customers using the on-premise version are urged to update their instances to version 026.3.1.10 immediately. To assist in identifying potential breaches, N-able has also provided an expanded list of IP addresses as indicators of compromise. Additionally, they have released a custom service template for automated checks against Windows device endpoints in N-central. However, N-able cautions that a clean scan does not necessarily mean an environment is unaffected, stressing the importance of thorough reviews of logs and account activities.
N-able Enhances Security with New N-central Hotfix Amid Exploitation Concerns
N-able released hotfixes after active exploitation of N-central enabled persistent attacker access to managed systems.


