vulnerability
N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist
Critical
Summary
N-able has released a second hotfix (Hotfix 2) to address a critical zero-day vulnerability (CVE-2026-18577) in its N-central RMM product, which was being actively exploited by threat actors. The vulnerability allows for remote administrative access and persistence within managed environments, and has been linked to a Cloudflare Tunnel service being established by attackers after gaining initial access. N-able is providing indicators of compromise (IoCs) and a custom service template to assist customers in assessing and mitigating the risk.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
