Skip to main content
CybersecurityVulnerability Management

N-able Bolsters Defenses as Attackers Exploit RMM Flaw

Modern tech company server room with rows of racks and a laptop screen in foreground.

"We are proactively expanding protections in response to ongoing monitoring of threat actors as they evolve their attack techniques," N‑able said, announcing a second hotfix for its N‑central Remote Monitoring and Management product.

N‑able statement and Hotfix 2

N‑able published Hotfix 2 as part of an active investigation into exploitation of a recently disclosed vulnerability in N‑central. The company said Hotfix 2 "is required, even if you already applied the earlier hotfix" and that it "supersedes Hotfix 1 with additional hardening measures to further protect you and your customers." N‑able characterized the update as a proactive expansion of protections in response to evolving attacker techniques.

The technical chain: CVE-2026-18577, Take Control, and Cloudflare Tunnel persistence

N‑able detected unusual activity within a customer's environment on July 31, 2026, which led to discovery of unknown threat actors exploiting a then-zero-day in the N‑central server tracked as CVE-2026-18577 (CVSS score: 8.2). The vulnerability impacts all versions prior to 2026.3.1.7 and, according to N‑able, relates to an incomplete fix for CVE-2026-18556 (CVSS score: 8.2). Both vulnerabilities allow authentication bypass and account takeover in susceptible versions and have been flagged as actively exploited by the U.S. Cybersecurity and Infrastructure Security Agency (CISA).

In the incidents observed by N‑able, attackers used the vulnerability to obtain administrative access remotely and then leveraged N‑central's Take Control feature to connect to systems inside the managed environment. After accessing those devices, the threat actors registered a new service for a Cloudflare Tunnel, a move N‑able said enabled persistence even after access to the N‑central server was revoked.

Who was affected and immediate guidance for on‑premise customers

N‑able confirmed a limited number of customers have been affected by the exploitation activity. The company advised customers running an on‑premise version to update their instances immediately to 026.3.1.10. N‑able emphasized that its investigation is ongoing and that additional indicators may be identified over time.

Indicators of Compromise and N‑central tooling

As part of its response, N‑able published an expanded set of IP addresses as indicators of compromise (IoCs):

  • 173.249.252[.]176
  • 173.249.252[.]200
  • 185.156.46[.]150
  • 23.234.94[.]43
  • 37.153.90[.]88
  • 37.19.210[.]32
  • 68.235.46[.]214
  • 68.235.46[.]235
  • 87.249.138[.]34
  • 92.118.112[.]181

To assist detection, N‑able also released a custom service template that automates checking for known IoCs against Windows device endpoints managed by N‑central. The company warned that "a clean result should not be interpreted as a guarantee that your environment has not been impacted," and recommended the template be used as one layer of assessment alongside "a thorough review of your environment, logs, and account activity."

What this means for technologists, affected enterprises, and regulators

Technologists and security teams: N‑able’s advisory directs immediate software updates for on‑premise instances to 026.3.1.10, deployment of the vendor’s IoC checks, and comprehensive log and account‑activity reviews to hunt for traces of Take Control misuse or a registered Cloudflare Tunnel service.

Affected enterprises and procurement leaders: organizations that rely on N‑central should confirm whether they operate on‑premise instances prior to 2026.3.1.7, apply the required hotfix, and treat a vendor-supplied "clean" check as only one component of a broader remediation and validation effort.

Regulators and response coordinators: CISA has flagged both CVE-2026-18577 and CVE-2026-18556 as actively exploited. That public designation, together with N‑able’s ongoing investigation and the persistence technique observed, frames the issue for coordinated incident response and continued monitoring.

Conclusion: N‑able’s Hotfix 2 is presented as an urgent, mandatory step for on‑premise users, issued against a vulnerability chain CISA has labeled actively exploited. The attack pattern N‑able described — remote administrative acquisition, use of Take Control to reach managed endpoints, and installation of a Cloudflare Tunnel service for persistence — changes the remediation calculus because revoking server access alone may not evict the attackers. N‑able's investigation remains active, and the company has warned that additional indicators may surface as that work continues.

Original story: https://thehackernews.com/2026/08/n-central-attackers-reach-managed.html