Attackers turned admin access into a route downstream, while N-able tells N-central customers to patch – again

N-able has confirmed that attackers exploiting a critical zero-day vulnerability in its N-central remote monitoring and management (RMM) platform successfully infiltrated customer networks. The vendor has subsequently released a second mandatory hotfix, version 2026.3.1.10, just days after an initial emergency patch.
The confirmed attacks leveraged CVE-2026-18577, a flaw that grants an unauthenticated attacker administrative access to N-central servers. N-able's investigation found that after gaining control of vulnerable N-central servers, attackers utilized the platform's "Take Control" feature to establish connections to systems within the environments managed by the compromised servers.
Once inside customer networks, the attackers registered a new Cloudflare Tunnel service. This action was intended to maintain persistence even if their initial access to the N-central server was disrupted. This specific behavior had previously been observed and reported by security researchers.
N-able stated that a "limited number" of its customers were affected by these intrusions. However, the company has not disclosed the exact number of affected customers, the quantity of downstream systems compromised, or the specific actions taken by the attackers once persistent access was established.
The newly released Hotfix 2 supersedes the first emergency fix, version 2026.3.1.7, which was issued on August 2. N-able explicitly instructed all on-premises N-central customers to install Hotfix 2 immediately, even if Hotfix 1 had already been applied. The company indicated that the new update includes additional hardening measures as it continues to monitor evolving threat actor techniques. Hosted N-central environments have already received the latest mitigations.
The initial discovery of the attacks occurred on July 31, when N-able's Adlumin managed detection and response service detected suspicious activity at a customer site. Further investigation revealed an active exploitation of a zero-day vulnerability against an N-central server, leading to the disclosure of CVE-2026-18577 and the release of the first hotfix.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-18577 to its Known Exploited Vulnerabilities catalog, mandating that federal agencies patch the flaw by August 6. This unusually short three-day deadline underscored the perceived urgency and risk associated with the vulnerability.
N-central platforms are a high-value target for attackers due to their role in managing numerous customer systems for managed service providers (MSPs). Compromising an N-central server can provide a gateway into the networks of an MSP's clients, rather than limiting an attacker to the initial server. Security researchers had previously noted that successful exploitation granted attackers the same level of N-central access typically reserved for trusted network operations and engineering personnel, which they then used to launch remote-control sessions against managed endpoints.
N-able has published a list of 10 IP addresses identified as being involved in the attacks and has provided a service template for customers to scan Windows endpoints for known indicators of compromise. The company cautioned that a clean scan should not be interpreted as a definitive all-clear, as the tool only checks for currently identified indicators, and further information may emerge as the investigation progresses.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.