N-able’s Critical Hotfix 2: Addressing Exploited Zero-Day Vulnerabilities in N-central

4

N-able Releases Critical Hotfix 2 for N-central as Attackers Persist on Managed Systems

Cybersecurity firm N-able has issued a second emergency hotfix for its N-central Remote Monitoring and Management platform after threat actors exploited a zero-day vulnerability to gain administrative access and establish persistence across managed customer environments.

The urgency of this situation is difficult to overstate. Attackers are not simply breaking in and leaving — they are planting digital footholds that survive even after organizations revoke server access. For managed service providers (MSPs) and their downstream customers, this represents a compounding threat that demands immediate action.


What Happened and How Attackers Got In

N-able first detected unusual activity within a customer's environment on July 31, 2026. That discovery led to the identification of an actively exploited zero-day vulnerability tracked as CVE-2026-18577, with a CVSS score of 8.2. The flaw affects all versions of N-central prior to 2026.3.1.7.

The vulnerability is particularly significant because it represents an incomplete fix for an earlier flaw. CVE-2026-18577 is directly related to CVE-2026-18556, which carries the same CVSS score of 8.2. Both vulnerabilities enable authentication bypass and full account takeover in susceptible versions of the platform. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has flagged both as actively exploited in the wild. Understanding the nature of these threats is critical — effective cyber threat intelligence gathering and analysis would have allowed some organizations to act on early warning signals before exploitation occurred.

Once inside, attackers moved quickly and deliberately. They used the vulnerability to obtain remote administrative access and then leveraged N-central's own Take Control feature to connect directly to systems within the managed environment. This is a textbook example of living-off-the-land tactics — using legitimate tools already trusted by the platform to avoid detection while leaving minimal forensic traces.

Why Incomplete Patches Create Dangerous Windows of Exposure

The relationship between CVE-2026-18556 and CVE-2026-18577 illustrates a pattern that security teams must recognise: threat actors actively probe patched systems for residual weaknesses in incomplete remediations. A patch that closes 90% of an attack surface can still leave an operational gap wide enough for a determined adversary to exploit.

Patch sequencing matters. A first fix does not always close every door, and organisations that treated the initial remediation as a resolved matter were left exposed to a follow-on attack using a closely related technique.


How Attackers Maintained Persistence

What makes this attack chain especially dangerous is what happened after initial access was established. Upon reaching managed devices, the threat actors registered a new service for a Cloudflare Tunnel. This technique allowed them to maintain a persistent communication channel back to attacker-controlled infrastructure — even after access to the N-central server itself was revoked.

The analogy is apt: the attackers didn't just crack the safe, they installed a hidden door before leaving. Revoking credentials closed the front entrance, but the back channel remained open and fully operational.

The Cloudflare Tunnel Technique Explained

Cloudflare Tunnels are a legitimate networking tool that creates outbound-only encrypted connections between a host and Cloudflare's network. Because the connection is outbound and encrypted, it can bypass many traditional perimeter defences and firewall rules that focus on blocking inbound traffic. When abused by threat actors, this creates a covert, resilient persistence mechanism that does not rely on the compromised platform remaining accessible.

This is not a flaw in Cloudflare's service — it is an example of attackers weaponising trusted, widely-used infrastructure to blend into normal network traffic. Security teams should audit all registered services on managed endpoints for unexpected Cloudflare Tunnel configurations, as these may indicate persistent footholds that survived credential revocation. Broader controls around securing and monitoring remote network access are directly relevant here, particularly for MSPs managing large distributed environments.

N-able confirmed that a limited number of customers were affected by the exploitation activity. However, the company has been careful to note that its investigation remains ongoing and the full scope of impact may not yet be known.


What Organisations Must Do Right Now

N-able has been explicit in its guidance: Hotfix 2 is not optional and it is not a duplicate of earlier communications. Organisations that already applied Hotfix 1 are still required to apply Hotfix 2 because it introduces additional hardening measures that supersede the earlier patch.

"We are proactively expanding protections in response to ongoing monitoring of threat actors as they evolve their attack techniques," N-able stated. "Hotfix 2 supersedes Hotfix 1 with additional hardening measures to further protect you and your customers."

Customers running an on-premise version of N-central are advised to update their instances to version 2026.3.1.10 immediately. N-able has also released a custom service template that provides an automated method to check Windows device endpoints within N-central for known indicators of compromise (IoCs).

However, the company issued an important caution alongside that tool. "A clean result should not be interpreted as a guarantee that your environment has not been impacted," N-able warned. "Our investigation is ongoing and additional indicators may be identified over time. We strongly recommend this be used as one layer of your assessment alongside a thorough review of your environment, logs, and account activity."

Confirmed Indicators of Compromise

The following IP addresses have been released as confirmed IoCs. Organisations should cross-reference these against firewall logs, SIEM alerts, and endpoint telemetry going back to at least July 31, 2026:

  • 173.249.252[.]176
  • 173.249.252[.]200
  • 185.156.46[.]150
  • 23.234.94[.]43
  • 37.153.90[.]88
  • 37.19.210[.]32
  • 68.235.46[.]214
  • 68.235.46[.]235
  • 87.249.138[.]34
  • 92.118.112[.]181

N-able's expanded IoC list reflects the evolving nature of the threat and suggests that attacker infrastructure may be distributed or rotating across multiple nodes. Organisations should not treat this list as static — additional indicators may emerge as the investigation progresses, and threat intelligence feeds should be monitored accordingly.

Immediate Action Steps for Security Teams and MSPs

Apply Hotfix 2 to N-central immediately and verify the version number reaches 2026.3.1.10 on all on-premise instances. Do not assume that applying Hotfix 1 provides sufficient protection — it does not.

Cross-reference the released IoC IP addresses against firewall logs, SIEM alerts, and endpoint telemetry. Audit all registered services on managed Windows endpoints for unexpected Cloudflare Tunnel configurations, which may indicate persistent attacker footholds that survived credential revocation.

Given the account takeover nature of both CVE-2026-18556 and CVE-2026-18577, this incident also highlights the importance of robust identity and access management practices as a foundational control. Authentication bypass vulnerabilities are significantly more damaging in environments where access controls, privilege separation, and account monitoring are not rigorously enforced.

MSPs in particular should communicate proactively with their downstream clients and initiate a full review of account activity and access logs rather than waiting for N-able's investigation to conclude. In an environment where attackers are actively adapting their techniques in real time, a layered and proactive assessment posture is no longer optional — it is a baseline expectation. The CISA Known Exploited Vulnerabilities Catalog provides a regularly updated reference point for tracking both CVEs associated with this incident and broader active exploitation trends.

You might also like