# N-able Enhances Security with New N-central Hotfix Amid Exploitation Concerns

*Published August 10, 2026*
*Source: [https://thehackernews.com/2026/08/n-central-attackers-reach-managed.html](https://thehackernews.com/2026/08/n-central-attackers-reach-managed.html)*

## Executive Summary

N-able has deployed new hotfixes for its N-central product to counteract a zero-day vulnerability actively exploited by attackers. This security update is crucial to preventing unauthorized access and maintaining system integrity.

## Article

N-able has issued a new set of hotfixes for its N-central Remote Monitoring and Management product following the discovery of a security flaw actively exploited by attackers. This latest update, labeled Hotfix 2, is designed to address vulnerabilities that have allowed threat actors to gain persistent access to managed systems. The company emphasized that Hotfix 2 introduces additional hardening measures beyond those provided in the previous update and is necessary even for those who have applied Hotfix 1. This move follows N-able's identification of unusual activity in a customer's environment on July 31, 2026, which led to the discovery of attackers exploiting a zero-day vulnerability, cataloged as CVE-2026-18577, with a high CVSS score of 8.2. This vulnerability, along with another known as CVE-2026-18556, allows attackers to bypass authentication and take over accounts in affected versions of the product. These vulnerabilities have been flagged as actively exploited by the U.S. Cybersecurity and Infrastructure Security Agency. Attackers have been observed using the flaw to gain administrative access, leveraging the Take Control feature to connect to systems within the N-central managed environment. Once inside, they established a Cloudflare Tunnel service to maintain persistence. N-able has confirmed that a limited number of customers have been affected. Customers using the on-premise version are urged to update their instances to version 026.3.1.10 immediately. To assist in identifying potential breaches, N-able has also provided an expanded list of IP addresses as indicators of compromise. Additionally, they have released a custom service template for automated checks against Windows device endpoints in N-central. However, N-able cautions that a clean scan does not necessarily mean an environment is unaffected, stressing the importance of thorough reviews of logs and account activities.
