N-able has issued Hotfix 2 for its N-central Remote Monitoring and Management (RMM) product, responding to ongoing exploitation of a recently disclosed zero-day vulnerability. The company warns that Hotfix 2 is mandatory even for customers who already applied the earlier hotfix, as it supersedes Hotfix 1 with additional hardening measures.
The advisory follows N-able’s detection of unusual activity in a customer environment on July 31, 2026, which led to the discovery of threat actors exploiting CVE-2026-18577 (CVSS 8.2), an authentication bypass and account takeover flaw affecting N-central versions prior to 2026.3.1.7. This vulnerability is an incomplete fix for CVE-2026-18556 (CVSS 8.2), both of which have been added to CISA’s Known Exploited Vulnerabilities catalog.
In observed attacks, the attackers gained remote administrative access to the N-central server and abused the Take Control feature to connect to managed systems. They then registered a new service for a Cloudflare Tunnel, ensuring persistence even after access to the N-central server was revoked. N-able confirmed that a limited number of customers were affected.
Customers running on-premise versions are urged to update to version 026.3.1.10 immediately. N-able has also published an expanded list of IP addresses as indicators of compromise (IoCs) and released a custom service template to automate IoC checks on Windows endpoints. The company cautions that a clean result does not guarantee an environment is unaffected, as the investigation is ongoing.
CVEs: CVE-2026-18577, CVE-2026-18556, CVE-2026-50522
Companies: N-able, Cloudflare, CISA
Products: N-central
Original source: thehackernews.com