CVE-2026-18577high
N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist
N-able has released Hotfix 2 for its N-central platform to address an actively exploited zero-day vulnerability. Attackers leveraged this flaw to gain administrative access, persist on managed systems using Cloudflare Tunnel, and maintain access even after the initial exploit was mitigated. The company confirmed a limited number of customers were affected and is providing additional indicators of compromise and tools for detection.