N-able has confirmed that attackers exploiting a critical zero-day vulnerability in its N-central remote monitoring and management (RMM) platform successfully infiltrated customer networks. The vendor has subsequently released a second mandatory hotfix, version 2026.3.1.10, just days after an initial emergency patch.
The confirmed attacks leveraged CVE-2026-18577, a flaw that grants an unauthenticated attacker administrative access to N-central servers. N-able's investigation found that after gaining control of vulnerable N-central servers, attackers utilized the platform's "Take Control" feature to establish connections to systems within the environments managed by the compromised servers.
Once inside customer networks, the attackers registered a new Cloudflare Tunnel service. This action was intended to maintain persistence even if their initial access to the N-central server was disrupted. This specific behavior had previously been observed and reported by security researchers.
N-able stated that a "limited number" of its customers were affected by these intrusions. However, the company has not disclosed the exact number of affected customers, the quantity of downstream systems compromised, or the specific actions taken by the attackers once persistent access was established.
The newly released Hotfix 2 supersedes the first emergency fix, version 2026.3.1.7, which was issued on August 2. N-able explicitly instructed all on-premises N-central customers to install Hotfix 2 immediately, even if Hotfix 1 had already been applied. The company indicated that the new update includes additional hardening measures as it continues to monitor evolving threat actor techniques. Hosted N-central environments have already received the latest mitigations.
The initial discovery of the attacks occurred on July 31, when N-able's Adlumin managed detection and response service detected suspicious activity at a customer site. Further investigation revealed an active exploitation of a zero-day vulnerability against an N-central server, leading to the disclosure of CVE-2026-18577 and the release of the first hotfix.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-18577 to its Known Exploited Vulnerabilities catalog, mandating that federal agencies patch the flaw by August 6. This unusually short three-day deadline underscored the perceived urgency and risk associated with the vulnerability.
N-central platforms are a high-value target for attackers due to their role in managing numerous customer systems for managed service providers (MSPs). Compromising an N-central server can provide a gateway into the networks of an MSP's clients, rather than limiting an attacker to the initial server. Security researchers had previously noted that successful exploitation granted attackers the same level of N-central access typically reserved for trusted network operations and engineering personnel, which they then used to launch remote-control sessions against managed endpoints.
N-able has published a list of 10 IP addresses identified as being involved in the attacks and has provided a service template for customers to scan Windows endpoints for known indicators of compromise. The company cautioned that a clean scan should not be interpreted as a definitive all-clear, as the tool only checks for currently identified indicators, and further information may emerge as the investigation progresses.






