N-able has issued N-central Hotfix 2 following continued investigation into malicious activity targeting its Remote Monitoring and Management (RMM) platform. The company says the update expands protections because threat actors are evolving their methods and, in some cases, maintaining access inside managed environments.
Importantly, Hotfix 2 is not optional for previously updated systems. N-able states that Hotfix 2 supersedes Hotfix 1 and must be installed even if you applied the earlier hotfix.
Why N-central Hotfix 2 was released
The release comes after N-able detected unusual activity in a customer environment on July 31, 2026. During that investigation, the company identified unknown threat actors exploiting a then-zero-day issue in the N-central server.
N-able frames the work as proactive hardening. In its public note, the vendor indicated it is expanding defenses in response to ongoing monitoring of attacker behavior and the way their techniques change over time.
The vulnerability behind the attack activity
N-able attributes the exploitation activity to CVE-2026-18577 with a CVSS score of 8.2. According to the vendor, the problem affects all versions prior to 2026.3.1.7.
The company also provides additional context: CVE-2026-18577 is related to an incomplete fix for CVE-2026-18556 (also rated 8.2). Both weaknesses can enable authentication bypass and account takeover in affected versions.
Both CVEs have been flagged as actively exploited by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), which underscores the operational risk for organizations that run susceptible N-central releases.
How attackers maintained access inside managed environments
Based on what N-able observed, the exploitation path included multiple steps. First, the attackers used the vulnerability to obtain remote administrative access to the N-central server.
After gaining those elevated capabilities, they leveraged a feature called Take Control to connect to systems that are managed within the N-central environment. Once inside those devices, the actors registered a new service using a Cloudflare Tunnel.
This design helped them keep persistence even after their access to the N-central server was revoked. In practice, that means defenders can’t assume that cutting off server access alone will fully eliminate the attacker’s foothold across endpoints.
Which customers are affected and what to update
N-able says it has confirmed that a limited number of customers were affected by exploitation activity. Even so, the vendor is advising organizations to take remediation actions immediately if they run vulnerable software.
For deployments using an on-premise version, N-able advises updating instances to 026.3.1.10 right away.
Because N-central Hotfix 2 is described as the required follow-up to earlier changes, organizations that already applied Hotfix 1 should still install Hotfix 2 to benefit from the additional hardening measures.
Hotfix 2 guidance: don’t stop at the first patch
N-able explicitly warns that Hotfix 2 is required even if you already installed the earlier hotfix. The company states that Hotfix 2 supersedes Hotfix 1 and includes additional hardening to further protect customers.
This is a common pattern in incident-driven patching: early mitigations reduce exposure, but attackers may continue to probe for weaknesses or work around partial fixes. Installing only the first update may leave gaps that a later hardening release closes.
Indicators of compromise (IoCs) shared by N-able
To support defenders, N-able also published an expanded set of indicators of compromise (IoCs). The list provided includes the following IP addresses:
- 173.249.252[.]176
- 173.249.252[.]200
- 185.156.46[.]150
- 23.234.94[.]43
- 37.153.90[.]88
- 37.19.210[.]32
- 68.235.46[.]214
- 68.235.46[.]235
- 87.249.138[.]34
- 92.118.112[.]181
These IoCs are intended to help teams check for suspicious communication patterns and potential links to the activity described by the vendor.
Automated IoC checking for Windows endpoints
In addition to publishing IoCs, N-able released a custom service template. The template provides an automated method to check for known IoCs against Windows device endpoints in N-central.
N-able also adds an important caveat: a “clean result” should not be treated as a guarantee that a system was unaffected. The investigation is ongoing, and additional indicators may be identified later.
Instead, the template should be viewed as one layer of assessment, alongside a thorough review of the environment, relevant logs, and account activity. This helps teams avoid false confidence when detections don’t hit known indicators.
Practical next steps for administrators
If you manage N-central and want to reduce risk after this disclosure, start with the remediation actions and then validate with broader checks.
1) Install N-central Hotfix 2
Confirm your N-central server version and ensure you are on the recommended update level for your deployment type. Because N-central Hotfix 2 supersedes Hotfix 1, you should treat Hotfix 2 as the “current” required step.
2) Review logs and account activity
Since the observed attacks included remote administrative access and later endpoint manipulation, logs around authentication, administrative actions, and feature use (such as Take Control) are essential.
3) Use the IoC template and investigate results
Run the provided service template to check Windows endpoints for the indicators N-able shared. If you see matches, prioritize deeper investigation rather than stopping at the initial detection.
4) Assume persistence attempts may exist
The reported registration of a Cloudflare Tunnel-based service is a reminder that attackers may keep access paths beyond the server itself. Look for signs of unexpected services, unusual networking behavior, and changes that occurred around the relevant timeline.
Conclusion
N-able’s N-central Hotfix 2 is a targeted response to continued exploitation of a high-impact RMM server flaw and reports of persistence within managed environments. The vendor stresses that Hotfix 2 is required even for systems already updated with Hotfix 1, and it recommends updating on-premise instances without delay.
Beyond patching, N-able encourages administrators to combine IoC checks with a careful review of logs and account activity to ensure the environment is fully assessed as the investigation progresses.
Source: https://thehackernews.com/2026/08/n-central-attackers-reach-managed.html
