N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist
N-able has released a second hotfix for its N-central RMM product to address ongoing exploitation of a security flaw, CVE-2026-18577, which attackers are leveraging to gain administrative access and establish persistence on managed systems.
Intelligence analysis by Gemini 2.5 Flash

Attackers are actively exploiting a zero-day vulnerability in N-able's N-central Remote Monitoring and Management (RMM) software, allowing them to bypass authentication, take over accounts, and gain administrative control. N-able has issued Hotfix 2, superseding the previous one, to counter evolving attack techniques, as threat actors have been observed using the 'Take Control' featur…
Imagine a special remote control that lets grown-ups fix many computers at once, like a super mechanic. Bad guys found a secret trick to use this remote control without permission. They can sneak into some computers and even leave a hidden backdoor, like a secret tunnel, so they can come back later even if the main remote control is fixed. The company that makes the remote control is now giving out a special update to block these bad guys and their secret tunnels.
Analysis
N-able's recent release of Hotfix 2 for its N-central product underscores the severe and evolving threat posed by active exploitation of a critical security flaw. This is not merely a patch for a theoretical vulnerability but a direct response to observed attacker activity, indicating a persistent and adaptive adversary. The company's proactive expansion of protections reflects the dynamic nature of these attacks, where threat actors continuously refine their techniques to bypass initial defenses.
N-central
The N-central Remote Monitoring and Management (RMM) product is a cornerstone for many managed service providers (MSPs), allowing them to oversee and manage numerous client systems remotely. The compromise of such a central tool presents a significant supply chain risk, as a single breach point can cascade into multiple customer environments. N-able's detection of unusual activity within a customer's environment on July 31, 2026, was the initial trigger, revealing a zero-day flaw being actively exploited. This incident emphasizes the need for continuous vigilance and rapid response in the RMM sector, given its pivotal role in IT infrastructure management.
CVE-2026-18577
The vulnerability, identified as CVE-2026-18577 with a CVSS score of 8.2, is particularly concerning because it is an incomplete fix for a prior flaw, CVE-2026-18556, also rated 8.2. Both vulnerabilities enable authentication bypass and account takeover, granting attackers remote administrative access. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has flagged these as actively exploited, elevating their severity. Attackers have been observed leveraging the 'Take Control' feature, a legitimate function of the RMM tool, to connect to systems within the N-central managed environment, effectively turning a management feature into an attack vector.
Cloudflare Tunnel
Upon gaining access to customer devices, the threat actors demonstrated a sophisticated understanding of persistence mechanisms by registering a new service for a Cloudflare Tunnel. This technique allows them to maintain access to compromised systems even after their initial access to the N-central server is revoked, making remediation significantly more challenging. N-able has confirmed that a limited number of customers have been affected, and has provided an expanded set of IP addresses as indicators of compromise (IoCs) to aid in detection. The company also released a custom service template to check for these IoCs, though it cautions that a clean result does not guarantee an unimpacted environment, stressing the need for thorough manual review.
Key points
- N-able released Hotfix 2 for N-central to address ongoing exploitation of a security flaw, CVE-2026-18577.
- Attackers are actively exploiting the vulnerability to gain administrative access and leverage the 'Take Control' feature on managed systems.
- Threat actors are establishing persistence on compromised devices by registering new services for Cloudflare Tunnels.
- CVE-2026-18577 is an incomplete fix for a previous vulnerability, CVE-2026-18556, both allowing authentication bypass and account takeover.
- N-able has provided expanded indicators of compromise (IoCs) and a custom service template to help customers detect the threat.
N-able's rapid response with Hotfix 2 and the provision of IoCs and a custom service template demonstrate a proactive approach to mitigating the threat. These measures, if promptly implemented by customers, can help contain the spread of the attack and prevent further compromise, strengthening the overall security posture of affected environments.
Despite the hotfix, the attackers' ability to establish persistence via Cloudflare Tunnels means that even patched N-central servers might still have compromised client systems. The ongoing nature of the investigation and the warning that a clean IoC scan isn't a guarantee of safety suggest that the full extent of the breach and its long-term implications may still be unfolding, posing a continued risk to affected customers.



