HackMyIP
← Back to News
2026-08-08 The Hacker News

N-able N-central Hotfix 2 Released as Attackers Exploit CVE-2026-18577

Zero-DayVulnerabilityAuthentication

N-able has shipped Hotfix 2 for its N-central Remote Monitoring and Management (RMM) platform, warning customers that the patch is mandatory even for those who already applied Hotfix 1. The new release introduces additional hardening measures after the company observed threat actors evolving their techniques against a previously disclosed flaw. The issue traces back to CVE-2026-18577 (CVSS 8.2), an authentication bypass vulnerability that affects all N-central versions prior to 2026.3.1.7, and which itself is an incomplete fix for the earlier CVE-2026-18556 (CVSS 8.2). Both vulnerabilities have been added to the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities catalog due to confirmed in-the-wild abuse.

According to N-able, the activity was first detected on July 31, 2026, when unusual behavior inside a customer's environment revealed threat actors exploiting CVE-2026-18577 as a zero-day against the N-central server. Once inside, the attackers obtained administrative access remotely and leveraged the platform's Take Control feature to pivot into endpoints managed by N-central. To maintain long-term access, the threat actors registered a new service for a Cloudflare Tunnel on compromised devices, allowing them to persist even after the customer's N-central credentials were revoked. A limited number of customers have been impacted so far, and on-premise users are being urged to upgrade immediately to version 2026.3.1.10.

N-able has published an expanded set of indicators of compromise (IoCs), including 10 IP addresses tied to the activity: 173.249.252.176, 173.249.252.200, 185.156.46.150, 23.234.94.43, 37.153.90.88, 37.19.210.32, 68.235.46.214, 68.235.46.235, 87.249.138.138, and 92.118.112.181. Defenders can validate suspicious infrastructure using a WHOIS lookup or scan exposed services with a port scanner to identify rogue Cloudflare Tunnel endpoints. The vendor has also released a custom service template that automates IoC checks across Windows endpoints managed by N-central, though it warns that a clean result should not be treated as proof of safety. Administrators should pair the scan with a thorough review of logs, account activity, and credential hygiene, including running any suspected credentials through a password checker to confirm they have not been compromised. The investigation remains ongoing, and additional indicators may surface in the coming days.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

Password Checker →Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

Password security basics →Two-factor authentication explained →How to create a strong password →